Attack on SCOM: From Domain User to Code Execution

The research shows that the default configuration of Microsoft System Center Operations Manager (SCOM) can be used to execute code on all managed hosts. The attack uses relay: an attacker with a standard domain account intercepts Data Access Service authentication and adds themselves to the list of SCOM administrators, gaining access to the Operations Console.
SCOM then becomes a centralized attack management platform: the console can be used to execute commands on all connected servers, while Run As and Action Account credentials can be extracted from agents. As a result, compromising a single domain user can lead to complete control over the monitoring infrastructure and all managed systems.
Vendors
Microsoft
Products
Data Access Service
Operations Console
Scom
System Center Operations Manager