Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Feb 26, 2026
Microsoft Configuration Manager Remote Code Execution Vulnerability
CVE-2025-47178
Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.
Affected products
2- Microsoft/Microsoft Configuration Managerv5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47178mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.