CVE detail
CVE-2024-43468 — Microsoft Configuration Manager SQL Injection Vulnerability
Published 2026-02-12 · Modified 2026-02-12 · Source kev
HIGH
severity
CVSS-derived band
0.6111
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2026-03-05
⚠ Actively exploited in the wild — CISA KEV listed 2026-02-12, federal remediation due 2026-03-05.
Description
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References