This is the payoff of site takeover: SCCM exists to deliver software to clients, so a Full Administrator (or anyone with the right deployment rights) can point that machinery at chosen targets and execute as SYSTEM on them. No exploit is involved; you are using the product as designed, against the estate.
Deploying to a collection#
# SharpSCCM: deploy to a device or a named collection; -s runs as SYSTEM (default is the logged-on user)
SharpSCCM.exe exec -d <device> -s -p "C:\Windows\System32\cmd.exe /c <payload>"
SharpSCCM.exe exec -n <collection-name> -s -p "<command>"
A device collection can be a single host or the whole estate, so the same action scales from one target to every managed machine.
Run Scripts and CMPivot#
Beyond full application deployments, the Run Scripts feature pushes PowerShell to clients, and CMPivot runs live queries across a collection. Both execute on the client and are faster and quieter than packaging an application:
# CMPivot runs a live query across a collection (recon or execution primitive)
# Run Scripts pushes approved PowerShell to selected devices as SYSTEM
Exploitation notes#
- Deployment runs in the client agent's context, which is SYSTEM, so this is local-admin-equivalent on every target without touching their credentials.
- SharpSCCM
execcan also force a client to authenticate to you (a coercion primitive) rather than run a payload, which pairs back into relay. - Collection scope is the blast radius: deploying to a broad collection is estate-wide code execution, so scope deliberately on an engagement.
- CMPivot is a useful recon tool even before full takeover if you hold read rights, inventorying every client live.
Tools#
- SharpSCCM (
exec): application and command deployment, and client coercion. - Native console / Run Scripts / CMPivot: deployment and live query once you hold administrative rights.