CVE-2024-43468: Microsoft Configuration Manager
EPSS81.0%No. 613 of 1739 in KEV
CVE year2024~2 yrs before listing
Same vendor in KEV389
Same product1
| Field | Value |
|---|---|
| Vendor | Microsoft |
| Product | Configuration Manager |
| Name | Microsoft Configuration Manager SQL Injection Vulnerability |
| Added to KEV | 2026-02-12 |
| US federal due date | 2026-03-05 |
| Ransomware use | Unknown |
| CWE | CWE-89 |
CISA description
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Microsoft Configuration Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-12.