Impact
Improper access control in Microsoft Configuration Manager permits an attacker who already has some level of authorized access to elevate their privileges over a network. The flaw is an authorization bypass (CWE‑284), allowing the attacker to gain higher privileges and potentially compromise system integrity and confidentiality within the network.
Affected Systems
Microsoft Configuration Manager releases 2503, 2509, and 2603 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is within an internal network; it requires the attacker to have some level of authorized access to a Configuration Manager instance and network connectivity.
OpenCVE Enrichment