Skip to content

Bypass Applocker on SCCM Managed Devices #24

@FredCyberSecurity

Description

@FredCyberSecurity

Hello.

On Config Manager(SCCM) managed devices, the INTERACTIVE user has read, execute and write permissions to C:\Windows\CCM\temp

This bypasses the default rule of applocker by dropping executables in this folder, and make sure that the running user has execute permission.

I have reported this to Microsoft, and they have confirmed that this is a issue, and will make a patch(without ETA)

More info here: https://github.com/FredCyberSecurity/Win11ApplockerBypass

I have some more applocker bypasses, but are waiting confirmation to publicly disclose this from Microsoft.

/Fred

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions