CVE-2025-55320

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
microsoftCNA
6.8 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
microsoftconfiguration_manager_2403
𝑥
< 5.00.9128.1035
microsoftconfiguration_manager_2409
𝑥
< 5.00.9132.1029
microsoftconfiguration_manager_2503
𝑥
< 5.00.9135.1008
𝑥
= Vulnerable software versions