ZeroHour

CVE-2024-43468

KEVmass

Unauthenticated SQL Injection to RCE in Microsoft Configuration Manager

CISA: Microsoft Configuration Manager SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
82%p100
Published
()
KEV added
AI analysis

CVE-2024-43468 is a SQL injection flaw (CWE-89) in Microsoft Configuration Manager that Microsoft rates critical (CVSS 3.1: 9.8), with a network attack vector requiring no privileges or user interaction, and it can escalate to remote code execution on affected site infrastructure. An attacker able to reach a vulnerable Configuration Manager component can submit crafted input that injects SQL commands against the underlying database, manipulate it, and gain code execution in the Configuration Manager environment. Affected deployments are the Configuration Manager current branch versions 2403, 2409, and 2503. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-02-12, confirming in-the-wild exploitation; EPSS is very high (82%), and ransomware use is not yet confirmed.

What to do: Install the updated Configuration Manager builds for branches 2403, 2409, and 2503 from Microsoft's monthly security update, per the vendor instructions required by the CISA KEV entry; no public PoC or workaround is documented. Prioritize site systems reachable from untrusted networks, since the CVSS vector is network-exploitable without authentication, and federal agencies must apply mitigations under BOD 22-01 within three weeks of the 2026-02-12 KEV addition or discontinue use. While patching, review logs for unexpected SQL activity against Configuration Manager databases to check for signs of exploitation.

Affected
Microsoft Configuration ManagerConfiguration Manager current branch 2403, 2409, and 2503 (CISA lists Microsoft Configuration Manager broadly)
Estimated exposure
mass≈100,000+ deployments worldwide (order-of-magnitude estimate) — Configuration Manager (SCCM) is among the most widely deployed Windows endpoint-management platforms in mid-size and large enterprises with a managed-device base in the tens of millions, so the number of vulnerable site installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Configuration Manager Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Configuration Manager
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
configuration manager 2403, configuration manager 2409, configuration manager 2503
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news