Summary
A vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet.
Impact
When a Windows device reports a specific SyncML status code during MDM communication, Fleet attempts to resend the original command by looking it up in a shared command table. A device-controlled value used in this lookup is not properly validated or scoped, allowing a malicious device to match commands belonging to other enrolled devices. Matched commands are then re-queued to the attacker's device and delivered on the next check-in.
Exploitation requires a device enrolled in Fleet's Windows MDM.
This issue does not affect instances where Windows MDM is disabled or environments with no enrolled Windows devices.
Workarounds
If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.
For more information
If you have any questions or comments about this advisory:
Email us at security@fleetdm.com
Join #fleet in osquery Slack
Credits
We thank @fuzzztf for responsibly reporting this issue.
Summary
A vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet.
Impact
When a Windows device reports a specific SyncML status code during MDM communication, Fleet attempts to resend the original command by looking it up in a shared command table. A device-controlled value used in this lookup is not properly validated or scoped, allowing a malicious device to match commands belonging to other enrolled devices. Matched commands are then re-queued to the attacker's device and delivered on the next check-in.
Exploitation requires a device enrolled in Fleet's Windows MDM.
This issue does not affect instances where Windows MDM is disabled or environments with no enrolled Windows devices.
Workarounds
If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.
For more information
If you have any questions or comments about this advisory:
Email us at security@fleetdm.com
Join #fleet in osquery Slack
Credits
We thank @fuzzztf for responsibly reporting this issue.