NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment
In this post, we detail our research into the Windows MDM enrolment protocol and demonstrate how a malicious MDM server can be weaponized to achieve a User Account Control (UAC) bypass and silent NT AUTHORITY\SYSTEM code execution with two clicks. By coaxing a user who is a member of the local administrators group into enrolling their device, an attacker can fully compromise the endpoint without triggering any UAC prompts.
POC: https://github.com/AmberWolfCyber/NachoMDM
Amberwolf
NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment
AmberWolf Security Research Blog