EXPOSURES › CVE-2024-43468
CVE-2024-43468
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated attacker exploited CVE-2024-43468 in Microsoft Configuration Manager, allowing SQL command execution.
An unauthenticated attacker exploited a SQL injection vulnerability in Microsoft Configuration Manager, enabling remote code execution without credentials.
Shame score — Unpatched, actively exploited vulnerability in a widely used DIB system.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |