Microsoft Configuration Manager SQL Injection Vulnerability Allowing Privilege Escalation

Vulnerability

A SQL injection vulnerability has been identified in Microsoft Configuration Manager, specifically in versions 2403, 2503, and 2409. This vulnerability allows an unauthorized attacker to inject malicious SQL, potentially leading to elevated privileges. The issue arises in the 'DuplicateAMTMachineRecord' method, where special elements are not properly neutralized, enabling local privilege escalation.

Impact

Exploitation of this vulnerability could allow an unauthorized attacker to gain administrative privileges within Microsoft Configuration Manager.

Remediation

Users can download the security update for Microsoft Configuration Manager 2403, 2503, or 2409 through the Microsoft Update Catalog.

Added: Oct 14, 2025, 6:37 PM
Updated: Oct 14, 2025, 9:08 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
4.9
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.