PT-2025-42104 · Microsoft · Configuration Manager

CVE-2025-59213

·

Published

2025-10-14

·

Updated

2026-02-13

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Configuration Manager (affected versions not specified)
Description An issue exists in Microsoft Configuration Manager where improper neutralization of special elements in SQL commands allows an attacker to inject malicious SQL code. Successful exploitation can lead to unauthorized privilege escalation on the affected system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13094
CVE-2025-59213

Affected Products

Configuration Manager