Microsoft Configuration Manager
cpe:2.3:a:microsoft:system_center_configuration_manager:*:*:*:*:*:*:*
A vulnerability in Microsoft Configuration Manager has been identified, allowing authentication bypass by spoofing. This issue enables an authorized attacker to impersonate users over an adjacent network. The vulnerability arises because Active Directory user accounts with certain user principal names (UPNs) were not properly synchronized to Microsoft Entra ID, creating an opportunity for spoofing attacks.
Exploitation of this vulnerability could allow an attacker to gain unauthorized administrative control over Microsoft Configuration Manager and its managed clients.
Users can download the security update for Microsoft Configuration Manager version 2409, 2503, or 2403 through the Microsoft Endpoint Configuration Manager update center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.