DEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi kalimer0x00 Elyassa @DEFCONConference
DEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi kalimer0x00 Elyassa  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
Microsoft Configuration Manager, better known as SCCM, has become my go-to target for red team operations. While multiple attack paths were uncovered recently, companies still struggle to close all security gaps. This is largely due to the solution's complexity and historical technical debt, which make it challenging to effectively address and mitigate all security vulnerabilities. Moreover, as it primarily manages computers, taking over an SCCM deployment often leads to the full compromise of the Active Directory, with less hassle than traditional attack paths.

In this talk, I'll be sharing insights gained from my research on the solution that led to the discovery of multiple 0 Day vulnerabilities, such as CVE-2024-43468, an unauthenticated SQL injection. After introducing key concepts, I'll delve into various techniques for performing reconnaissance, tips for understanding the hierarchy and tricks for bypassing certain security boundaries. The session will also cover the discovered vulnerabilities that can lead to the compromise of the deployment.

After showcasing post-exploitation techniques from database access, I'll introduce a battle-tested open-source tool that implements them. And for those interested in persistence, a technique for installing a backdoor as a legitimate servicing endpoint will be shared.
DEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi kalimer0x00 ElyassaDEF CON 33 Recon Village -  Inside the Shadows Tracking RaaS Groups, Cyber Threats - John DilgenDEF CON 33 - Emulating Embedded Linux Devices at Scale w LightTouch Firmware Rehosting - S PolkeDEF CON 33  Voting Village - Risk Limiting Audits: What They Are and Arent - Philip StarkDEF CON 34 - Video Team - Ham Radio Village  - Marvin Goes HAMDEF CON 31 - The Art of Compromising C2 Servers  A Web App Vulns Perspective - Vangelis StykasDEF CON 32  - Manufacturing Lessons Learned, Lessons Taught - Tim ChaseDEF CON 34 - Video Team - EmbeddedSystems VillageDEF CON 33 - The UnRightful Heir   My dMSA Is Your New Domain Admin - Yuval GordonDEF CON 33 - Voting Village -  Its Not Safe Yet: Online Voting in Practice - Michael SpecterDEF CON 32 - Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back - S1nn3rDEF CON 33 - Breaking Wi-Fi Easy Connect: A Security Analysis of DPP - George Chatzisofroniou
DEFCONConference |

DEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi 'kalimer0x00' Elyassa

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER