Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could accept attacker-controlled identity claims, enabling enrollment of unauthorized devices under arbitrary Azure AD user identities. Versions 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fix the issue. If an immediate upgrade is not possible, affected Fleet users should temporarily disable Windows MDM.
The vulnerability (CWE-347 — missing verification of cryptographic signature) consists in Fleet not verifying JWT signatures transmitted during the Windows MDM registration process. As a result, the system accepts tokens crafted by an attacker containing arbitrarily specified identity data. This allows spoofing of false identity claims associated with any Azure AD user account and performing unauthorized device registration as a trusted device.
An attacker can register unauthorized devices in the Fleet system by impersonating any Azure AD user, leading to violation of integrity and confidentiality of data managed by the MDM platform.
Update Fleet to version 4.78.3, 4.77.1, 4.76.2, 4.75.2, or 4.53.3, depending on the branch in use. If immediate patching is not possible, the vendor recommends temporarily disabling the Windows MDM feature.
Fleetdm Fleet versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFleetdm Fleet
APPFleetdm4.77.0< 4.53.34.75.0 – 4.75.2 (excl.)4.76.0 – 4.76.2 (excl.)4.78.0 – 4.78.3 (excl.)
Related vulnerabilities
Obejście uwierzytelniania SAML w Fleet — nieautoryzowany dostęp przez SSO
Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows M...
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service ...
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows M...
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption ...