CVE-2025-55320

EUVD-2025-34424
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
microsoftCNA
6.8 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
microsoftconfiguration_manager_2403
𝑥
< 5.00.9128.1035
microsoftconfiguration_manager_2409
𝑥
< 5.00.9132.1029
microsoftconfiguration_manager_2503
𝑥
< 5.00.9135.1008
𝑥
= Vulnerable software versions