Remote Code Execution Vulnerability Affects Microsoft Configuration Manager
CVE-2024-43468

9.8CRITICAL

Key Information:

Vendor
Microsoft
Status
Microsoft Configuration Manager
Vendor
CVE Published:
8 October 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability in Microsoft Configuration Manager allows remote code execution, potentially enabling attackers to gain control over affected systems. This security flaw can be exploited if an attacker sends a specially crafted request to the vulnerable application, leading to unauthorized execution of malicious code. Organizations using impacted versions of Microsoft Configuration Manager should prioritize applying available updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft Configuration Manager Unknown 1.0.0 < 5.00.9106

Microsoft Configuration Manager Unknown 1.0.0 < 5.00.9122

Microsoft Configuration Manager Unknown 1.0.0 < 5.00.9128

News Articles

Update Now As Critical Windows 9.8/10 Vulnerability Confirmed

Security professionals have issued an update warning for Windows users as a critical vulnerability in Microsoft’s configuration manager is confirmed.

3 months ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Forbes

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed1 News Article(s)
.