#NullconBerlin2025 | LPEPM - Tricking Microsoft EPM To Do Our Bidding by Philip & Rotem

33:53 · 04 Sep 2025 – 05 Sep 2025 · YouTube

About this talk

This talk explores the internals of Microsoft Endpoint Privilege Management (EPM), examining how elevation policy enforcement is intended to restrict high-privilege task execution. The speakers, Philip Tsukerman and Rotem Salinas, present several vulnerabilities that enable attackers to elevate arbitrary code execution, despite EPM's intended safeguards. They detail their process of reverse-engineering EPM binaries to uncover the first vulnerability, followed by techniques to bypass patches and resurrect flaws after they have been addressed. Additionally, the session discusses design issues within EPM that can lead to privilege escalation and highlights the challenges of creating a truly LPE-resistant solution.

From event

Nullcon Berlin 2025

04 Sep 2025 – 05 Sep 2025

All event videos
Back to Watch