Executive brief
Microsoft Configuration Manager, a tool used by organizations to manage and deploy software across large fleets of computers, contains a security flaw in its access control mechanisms. An attacker who already has basic user access to the network could exploit this weakness to gain administrative control over the management system. This could allow them to deploy malicious software, access sensitive data, or disrupt operations across the entire managed environment.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft Configuration Manager. The flaw allows an authenticated attacker with low-level privileges to escalate their permissions to a higher level, potentially gaining full administrative control. The attack is reachable over the network and does not require user interaction. Affected versions include Configuration Manager releases prior to versions 2503, 2509, and 2603. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Configuration Manager < 2503
- Microsoft Configuration Manager 2509 < 2509
- Microsoft Configuration Manager 2603 < 2603
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD.
- 2026-07-14: patched: Security updates released by Microsoft.