A zero-day exploit chain affecting Microsoft Configuration Manager (SCCM) has been documented as CVE-2026-47301, allowing a domain user to escalate control through the SCCM SMS Provider. The attack involves planting a malicious adsource.dll—or similarly named adsource_*.dll library—in the SMS Provider bin\X64 directory, where it can be loaded by SCCM components in a privileged service context and yield SYSTEM-level code execution on hosts assigned the SMS Provider role.
Splunk released detections for the exploit indicators, including creation or modification of adsource.dll files in the SMS Provider directory and suspicious child processes spawned by the SCCM SMS Executive service, smsexec.exe. Security teams should treat shells, scripting engines, or post-exploitation tools launched by smsexec.exe as evidence of successful service exploitation and a full compromise of the affected host, while validating file-write alerts against authorized SCCM upgrades and hotfix activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Enterprise Security provides the "Windows SCCM Smsexec Spawned a Suspicious Child Process" detection, which flags shells, scripting engines, and post-exploitation tools launched by smsexec.exe. A confirmed alert indicates successful SCCM SMS Executive service exploitation and a full compromise of the affected host.
Splunk Enterprise Security provides the "Windows SCCM Adsource DLL Was Planted In SMS Provider Directory" detection for creation or modification of adsource.dll or adsource_*.dll in the SCCM SMS Provider bin\X64 directory. The analytic is intended to detect DLL side-loading associated with CVE-2026-47301.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.