#NullconBerlin2025 | LPEPM - Tricking Microsoft EPM To Do Our Bidding by Philip & Rotem
About this talk
This talk explores the internals of Microsoft Endpoint Privilege Management (EPM), examining how elevation policy enforcement is intended to restrict high-privilege task execution. The speakers, Philip Tsukerman and Rotem Salinas, present several vulnerabilities that enable attackers to elevate arbitrary code execution, despite EPM's intended safeguards. They detail their process of reverse-engineering EPM binaries to uncover the first vulnerability, followed by techniques to bypass patches and resurrect flaws after they have been addressed. Additionally, the session discusses design issues within EPM that can lead to privilege escalation and highlights the challenges of creating a truly LPE-resistant solution.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03