Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-47179

Опубликовано: 11 нояб. 2025
Источник: msrc
CVSS3: 6.7
EPSS Низкий

Описание

Configuration Manager Elevation of Privilege Vulnerability

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

FAQ

How could an attacker exploit this vulnerability?

An attacker with access to any user account assigned the built-in CMPivot Administrator security role could exploit this vulnerability by escalating privileges. Specifically, they could assign themselves—or another account—the Full Administrator role (or any other elevated role), or modify existing role permissions. This would allow them to bypass intended security boundaries and gain unrestricted access across the hierarchy.

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An authorized attacker who successfully exploited this vulnerability could gain configuration manager administrator privileges.

Обновления

ПродуктСтатьяОбновление
Microsoft Configuration Manager 2403
Microsoft Configuration Manager 2503
Microsoft Configuration Manager 2409

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 22%
0.00069
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
3 месяца назад

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
github
3 месяца назад

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
fstec
3 месяца назад

Уязвимость программного обеспечения управления ИТ-инфраструктурой Microsoft Configuration Manager, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 22%
0.00069
Низкий

6.7 Medium

CVSS3