CVE-2025-59501 is an authentication bypass vulnerability affecting Microsoft Configuration Manager versions 2403, 2409, and 2503. An authenticated attacker can exploit this flaw over an adjacent network to perform spoofing. With a CVSS score of 4.8 (Medium), the attack requires low privileges and high attack complexity, potentially leading to high confidentiality impact but no integrity or availability impact. Currently, there is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.00.9128.1037CPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2403:*:*:*:*:*:*:*:* | ||
< 5.00.9132.1031CPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2409:*:*:*:*:*:*:*:* | ||
< 5.0.9135.1013CPE matchmatch criteria | cpe:2.3:a:microsoft:configuration_manager_2503:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.