Skip to content
Threat Feed
rumour rumour

NachoMDM Vulnerability in Windows MDM Enrollment

NachoMDM is a vulnerability within the Windows Mobile Device Management (MDM) enrollment process that allows an attacker to achieve UAC bypass and execute arbitrary code with SYSTEM privileges.

NachoMDM identifies a critical security flaw in the Windows Mobile Device Management (MDM) enrollment mechanism. Discovered by researchers and detailed in August 2026, this vulnerability permits an attacker to intercept or manipulate the standard enrollment workflow, leading to a bypass of User Account Control (UAC). By weaponizing this process, an attacker can escalate privileges from a standard user context to NT AUTHORITY\SYSTEM. The vulnerability exploits the trust relationship and the elevated processes invoked during device configuration, allowing for arbitrary code execution. This is particularly significant for environments that allow self-enrollment or rely on automated MDM provisioning, as an attacker with initial local access can weaponize the enrollment sequence to gain full control of the Windows operating system.

Impact

The vulnerability results in a total compromise of the host system through privilege escalation to SYSTEM level. Organizations utilizing Windows MDM enrollment are at risk, particularly those that permit non-administrative users to initiate enrollment processes. Successful exploitation allows for persistent access, credential theft, and full system control.

Recommendation

Prioritized actions for detection engineering and security teams:

  • Monitor the Windows MDM enrollment log (Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin) for anomalous initiation or high-frequency failures that may indicate enrollment process tampering.
  • Review and restrict permissions for initiating MDM enrollment to authorized service accounts or administrative roles only.
  • Audit existing MDM configurations to ensure that enrollment endpoints are strictly hardened and that no unauthorized enrollment profiles are active in the environment.

Immediate actions

Audit MDM enrollment policies and restrict self-enrollment privileges

IT Operations 48h

Threat Hunt

Search for unauthorized or non-standard Windows MDM enrollment processes

T1548.002 high high confidence hunt now

Data: Event logs for Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider