High severity8.8NVD Advisory· Published Oct 14, 2025· Updated Jun 17, 2026
CVE-2025-59213
CVE-2025-59213
Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
Affected products
6- cpe:2.3:a:microsoft:configuration_manager_2403:*:*:*:*:*:*:*:*Range: <5.00.9128.1035
cpe:2.3:a:microsoft:configuration_manager_2409:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:configuration_manager_2409:*:*:*:*:*:*:*:*range: <5.00.9132.1029
- (no CPE)range: 1.0.0
- cpe:2.3:a:microsoft:configuration_manager_2503:*:*:*:*:*:*:*:*Range: <5.00.9135.1008
- Range: 1.0.0
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59213nvdVendor Advisory
News mentions
0No linked articles in our index yet.