logo

MSSQL and SCCM Elevation of Privilege Vulnerabilities

ID: 2e8558de-ecf0-56d8-b209-9557e3c74b61

STIX ID: report--2e8558de-ecf0-56d8-b209-9557e3c74b61

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-30

Author: Chris Thompson

...
...

This post details the discovery and coordinated disclosure of two Microsoft privilege‑escalation vulnerabilities: CVE‑2025‑49758 in MSSQL (ALTER ANY LOGIN can reset passwords of securityadmin / IMPERSONATE ANY LOGIN principals to obtain sysadmin) and CVE‑2025‑47179 in Configuration Manager (CMPivot Administrator role granted excessive permissions enabling Full Administrator escalation); the author includes reproduction steps, BloodHound detection integration, remediation guidance, and timelines showing Microsoft released fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.