Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-47301

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Configuration Manager Elevation of Privilege Vulnerability

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

FAQ

What privileges could be gained by an attacker who successfully exploited this vulnerability?

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

How could an attacker exploit this vulnerability?

An attacker could exploit this vulnerability by sending specially crafted requests to the affected service interface, allowing them to upload content without the required permissions. By doing so, an authenticated attacker could leverage this unauthorized access to introduce malicious or unintended content into the system, leading to elevated capabilities beyond their intended level.

Обновления

ПродуктСтатьяОбновление
Microsoft Configuration Manager 2503
Microsoft Configuration Manager 2509
Microsoft Configuration Manager 2603

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

N/A

EPSS

Процентиль: 42%
0.00537
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
21 день назад

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
github
21 день назад

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

EPSS

Процентиль: 42%
0.00537
Низкий

8.8 High

CVSS3