Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-59501

Опубликовано: 24 окт. 2025
Источник: msrc
CVSS3: 4.8
EPSS Низкий

Описание

Microsoft Configuration Manager Spoofing Vulnerability

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

For the vulnerability, this means the exploitation requires a specific and uncommon condition: an Active Directory user account must exist with a matching user principal name (UPN) that was not properly synchronized to Microsoft Entra ID.

How could an attacker exploit this vulnerability?

An attacker could exploit this vulnerability by modifying the user principal name (UPN) of a valid Microsoft Entra ID account or create a new Account to impersonate an Active Directory user with the same UPN that was not synchronized to Entra ID. Successful exploitation could allow the attacker to gain unauthorized administrative control over Microsoft Configuration Manager and its managed clients.

According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?

This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.

Обновления

ПродуктСтатьяОбновление
Microsoft Configuration Manager 2403
Microsoft Configuration Manager 2503
Microsoft Configuration Manager 2409

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

EPSS

Процентиль: 44%
0.00217
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
3 дня назад

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

CVSS3: 4.8
github
3 дня назад

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

EPSS

Процентиль: 44%
0.00217
Низкий

4.8 Medium

CVSS3