PT-2025-42104 · Microsoft · Configuration Manager

Published

2025-10-14

·

Updated

2026-02-13

·

CVE-2025-59213

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Configuration Manager (affected versions not specified)
Description An issue exists in Microsoft Configuration Manager where improper neutralization of special elements in SQL commands allows an attacker to inject malicious SQL code. Successful exploitation can lead to unauthorized privilege escalation on the affected system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-13094
CVE-2025-59213

Affected Products

Configuration Manager