https://reddit.com/r/netsec/comments/1i2vo90/microsoft_configuration_manager_configmgr_sccm/: Microsoft Configuration Manager (ConfigMgr / SCCM) 2403 Unauthenticated SQL injections (CVE-2024-43468)
Published Jan 16, 2025
·Updated
Affected Software
1 affected component
Microsoft Configuration Manager
Frequently Asked Questions
1
What is the severity of CVE-2024-43468?
CVE-2024-43468 is classified as a critical vulnerability due to its potential to allow unauthenticated remote attackers to exploit SQL injection flaws.
2
How do I fix CVE-2024-43468?
To mitigate CVE-2024-43468, apply the latest security update from Microsoft for Configuration Manager as soon as it is available.
3
What systems are affected by CVE-2024-43468?
CVE-2024-43468 affects all supported versions of Microsoft Configuration Manager where proper input validation is not enforced.
4
How can CVE-2024-43468 be exploited?
CVE-2024-43468 can be exploited by sending specially crafted SQL queries to vulnerable endpoints in Microsoft Configuration Manager.
5
Is there a workaround for CVE-2024-43468 before a patch is released?
While waiting for a patch for CVE-2024-43468, it is recommended to restrict network access to the Configuration Manager's database server.