HomeSecurityCISA: Microsoft Configuration Manager Vulnerability in KEV Catalog

CISA: Microsoft Configuration Manager Vulnerability in KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to federal government agencies, asking them to immediately patch their systems against a critical vulnerability in Microsoft Configuration Manager. The vulnerability, which was patched by Microsoft in October 2024, is now being actively exploited in real-world attacks, significantly increasing the threat level.

CISA Microsoft Configuration Manager Vulnerability

CISA's move highlights once again how a "theoretical" vulnerability can turn into a real tool in the hands of cybercriminals, especially when it concerns critical IT management platforms.

What is Microsoft Configuration Manager and why is it so important?

Microsoft Configuration Manager, also known as ConfigMgr or formerly SCCM (System Center Configuration Manager), is one of the most essential IT management tools in large organizations. It is used to centrally manage thousands of Windows servers and workstations, enabling the installation of updates, software deployment, and device monitoring in corporate and government networks.

See also: Hackers exploit serious BeyondTrust vulnerability

This means that a successful attack on ConfigMgr does not just affect a single system, but can provide access to an organization's entire infrastructure.

CVE-2024-43468: SQL Injection leading to Remote Code Execution

The vulnerability, which has been recorded as CVE-2024-43468 and was first reported by Synacktiv , is a SQL injection vulnerability that could allow remote attackers, without privileges, to gain code execution (RCE).

Simply put, an attacker can send specially crafted requests to a vulnerable server and execute arbitrary commands with the highest level of privileges, both on the server and the Configuration Manager database.

Microsoft had warned at the time that the vulnerability was due to unsafe input processing, allowing commands to be executed on critical system components.

CISA: Microsoft Configuration Manager Vulnerability in KEV Catalog

From “less likely exploit” to an active attack weapon

In October 2024, when the patch was released, Microsoft classified the exploit as “Exploitation Less Likely”, estimating that creating working attack code would require expertise, proper timing, and sophisticated techniques.

See also: Google-Intel security audit reveals serious TDX vulnerability

However, the data changed quickly. On November 26, 2024, Synacktiv published proof-of-concept exploit code for CVE-2024-43468, about two months after the security updates were released.

This point is critical: when a PoC code becomes public, the possibility of mass exploitation increases dramatically, as even less experienced attackers can adapt it for attacks.

CISA now calls it “actively exploited”

Although Microsoft has not yet released further details about the extent of the attacks, CISA has listed CVE-2024-43468 as being actively exploited.

The agency added the vulnerability to the KEV List and ordered federal agencies (FCEB) to implement the updates no later than March 5, in accordance with Binding Operational Directive (BOD) 22-01.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What does this mean for the private sector?

Although BOD 22-01 only directly concerns government agencies, CISA called on all organizations—including private sector companies—to immediately protect their systems.

See also: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Aveva, Phoenix Contact

CISA: Microsoft Configuration Manager Vulnerability in KEV Catalog

Platforms like ConfigMgr are found in thousands of corporate networks worldwide. A successful exploit can lead to ransomware attacks, data theft, or complete IT infrastructure collapse.

Patches are not optional

The case of CVE-2024-43468 is yet another example of why security updates should never be delayed. A patch that was initially considered “difficult to exploit” turned into an active attack tool within a few months.

For organizations using Microsoft Configuration Manager, immediate upgrades and continuous security monitoring are now a given.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS