Windows Agentless C2: (Ab)using the MDM Client Stack

No ratings

Presented at BlackHat USA 2023 by

This presentation will uncover the potential of harnessing the Windows Mobile Device Management (MDM) client stack to create an agentless Command and Control (C2) system. We will dive deep into the MDM infrastructure, exposing new vulnerabilities and demonstrating their potential for abuse.As a modern alternative to Group Policy Objects (GPO), Windows MDM enables extensive device management capabilities. We will present an in-depth analysis of the Windows MDM client architecture, focusing on the MDM Enrollment and MDM Management protocols. Furthermore, we will delve into the internals of the MDM management policies, exploring their creation and the numerous OS components managed through these policies.Throughout the talk, we will tackle the challenges and constraints of developing an agentless C2 system for Windows devices. We will show how this can be done by controlling both the MDM enrollment client and the MDM server components. On the client side, we will demonstrate multiple new vulnerabilities allowing exploitation of the MDM enrollment client from unprivileged contexts. On the server side, we will showcase a sophisticated custom C2 system designed for MDM-enrolled devices, enabling precise device control while abstracting the complexities of the MDM protocols. Finally, we will showcase a proof-of-concept (PoC) that demonstrates the end to end attack flow.This presentation will provide extensive analysis, live demos, detection opportunities, and a release of the underlying source code. We will discuss the implications of this research, security risks, and the impact of abusing the Windows MDM stack to create an evasive agentless C2 system. Don't miss this unique opportunity to delve into the world of Windows MDM exploitation!