Exploited Vulnerabilities Daily
🌐 English

Home › Microsoft

CVE-2024-43468: Microsoft Configuration Manager

EPSS81.0%No. 613 of 1739 in KEV
CVE year2024~2 yrs before listing
Same vendor in KEV389
Same product1
FieldValue
VendorMicrosoft
ProductConfiguration Manager
NameMicrosoft Configuration Manager SQL Injection Vulnerability
Added to KEV2026-02-12
US federal due date2026-03-05
Ransomware useUnknown
CWECWE-89

CISA description

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

NVD — CVE-2024-43468

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Microsoft Configuration Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-12.