Researchers detailed attack paths in Microsoft System Center Operations Manager (SCOM) that can let a low-privilege domain user gain SCOM administrative rights and execute tasks on managed systems. The principal technique coerces authentication from a SCOM Management Server whose MSOMSdkSvc Data Access Service SPN is assigned to the computer account, then relays NTLM authentication to the OperationsManager SQL database to add an attacker-controlled SID to the AzMan_Role_SIDMember authorization table. The resulting SCOM access can be used through the Operations Console to run tasks under configured Action Accounts, potentially reaching SYSTEM privileges on monitored domain controllers.
Researchers also warned that SCOM Action Account and Run As credentials are stored as DPAPI-protected registry data on managed hosts and may be recovered by local administrators, particularly where Run As accounts use less-secure credential distribution. Recommended defenses include moving the Data Access Service identity and SPN to a gMSA, limiting Run As credential distribution, using SYSTEM Action Accounts where appropriate, disabling the web-console PowerShell widget, and auditing LDAP, SQL, and network activity associated with relay and authorization changes; Microsoft Event ID 1644 can provide visibility into costly or anomalous LDAP queries.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers described attack paths in Microsoft System Center Operations Manager that can allow a low-privilege domain user to relay coerced Management Server authentication to the OperationsManager SQL database, add an attacker SID to a SCOM administrative role, and execute tasks on managed endpoints. The disclosure also detailed recovery of locally stored DPAPI-protected Action and Run As credentials by administrators of managed hosts, along with mitigations and detection guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
guidepointsecurity.com
Open sourcelearn.microsoft.com
Open sourcespecterops.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.