NachoMDM Vulnerability in Windows MDM Enrollment
NachoMDM is a vulnerability within the Windows Mobile Device Management (MDM) enrollment process that allows an attacker to achieve UAC bypass and execute arbitrary code with SYSTEM privileges.
NachoMDM identifies a critical security flaw in the Windows Mobile Device Management (MDM) enrollment mechanism. Discovered by researchers and detailed in August 2026, this vulnerability permits an attacker to intercept or manipulate the standard enrollment workflow, leading to a bypass of User Account Control (UAC). By weaponizing this process, an attacker can escalate privileges from a standard user context to NT AUTHORITY\SYSTEM. The vulnerability exploits the trust relationship and the elevated processes invoked during device configuration, allowing for arbitrary code execution. This is particularly significant for environments that allow self-enrollment or rely on automated MDM provisioning, as an attacker with initial local access can weaponize the enrollment sequence to gain full control of the Windows operating system.
Impact
The vulnerability results in a total compromise of the host system through privilege escalation to SYSTEM level. Organizations utilizing Windows MDM enrollment are at risk, particularly those that permit non-administrative users to initiate enrollment processes. Successful exploitation allows for persistent access, credential theft, and full system control.
Recommendation
Prioritized actions for detection engineering and security teams:
- Monitor the Windows MDM enrollment log (Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin) for anomalous initiation or high-frequency failures that may indicate enrollment process tampering.
- Review and restrict permissions for initiating MDM enrollment to authorized service accounts or administrative roles only.
- Audit existing MDM configurations to ensure that enrollment endpoints are strictly hardened and that no unauthorized enrollment profiles are active in the environment.
Immediate actions
Audit MDM enrollment policies and restrict self-enrollment privileges
Threat Hunt
Search for unauthorized or non-standard Windows MDM enrollment processes
Data: Event logs for Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider