Microsoft
Microsoft Configuration Manager 2503: vulnerabilidades y CVE
Microsoft Configuration Manager 2503 tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-43468 | Crítica (9.8) | 81% | ⚠ Explotación activa | 8 oct 2024 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-47301 | Alta (8.8) | 0.78% | — | 14 jul 2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-47179 | Media (6.7) | 0.35% | — | 11 nov 2025 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59501 | Media (4.8) | 3.0% | — | 31 oct 2025 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. |
| CVE-2025-59213 | Alta (8.8) | 0.37% | — | 14 oct 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. |
| CVE-2025-55320 | Media (6.8) | 0.68% | — | 14 oct 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. |
| CVE-2025-47178 | Alta (8) | 2.7% | — | 8 jul 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. |
| CVE-2024-43468 | Crítica (9.8) | 81% | ⚠ Explotación activa | 8 oct 2024 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.