Junglewise Threat Intelligence

CVE-2024-43468: Microsoft Configuration Manager SQL injection

CVE-2024-43468 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-02-12

Technologies: Microsoft Configuration Manager. Vendors: Microsoft.

Executive brief

Microsoft Configuration Manager, a tool used by IT departments to manage and secure large fleets of computers, contains a critical security flaw. An attacker can exploit this vulnerability over the network without needing any login credentials to take control of the server or its database. This could lead to a total compromise of the IT management infrastructure, allowing unauthorized software deployment or data theft across the organization.

Technical details

A SQL injection vulnerability (CWE-89) exists in Microsoft Configuration Manager due to improper neutralization of special elements in SQL commands. An unauthenticated attacker can exploit this by sending specially crafted network requests to the target environment. Because these requests are processed in an unsafe manner, the attacker can execute arbitrary commands on the server or the underlying database. This vulnerability has been observed being exploited in the wild, and Microsoft has released updates to address the issue across several versions including 2303 through 2503.

Affected products

  • Microsoft Configuration Manager 2303, 2309, 2403, 2409, 2503

Timeline

  • 2024-10-08: disclosed: Initial disclosure by Microsoft
  • 2026-02-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-02-12: exploited: Confirmed active exploitation in the wild

Related threats