Microsoft Configuration Manager Elevation of Privilege Vulnerability

Vulnerability

A vulnerability allowing improper access control in Microsoft Configuration Manager has been identified. This issue enables an authorized attacker to elevate privileges over a network. The vulnerability exists in Microsoft Configuration Manager versions 2503, 2603, and 2509.

Impact

Exploitation of this vulnerability could allow an authenticated attacker to gain SYSTEM privileges on the affected system.

Remediation

Users can download the security update for Microsoft Configuration Manager 2503, 2603, or 2509 via the Microsoft Endpoint Configuration Manager console. For detailed guidance, refer to the Microsoft Knowledge Base articles KB38232642 for versions 2603 and 2503, and KB37864969 for version 2509.

Added: Jul 15, 2026, 5:56 AM
Updated: Jul 15, 2026, 5:56 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.