CVE-2025-59213

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges locally.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
microsoftCNA
8.4 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
microsoftconfiguration_manager_2403
𝑥
< 5.00.9128.1035
microsoftconfiguration_manager_2409
𝑥
< 5.00.9132.1029
microsoftconfiguration_manager_2503
𝑥
< 5.00.9135.1008
𝑥
= Vulnerable software versions