CVE-2024-43468 is a critical Remote Code Execution vulnerability affecting Microsoft Configuration Manager versions 2403, 2409, and 2503. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and extensive media coverage. Despite the lack of public exploit code on platforms like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2403:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2409:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2503:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.