CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks
ID: b48095ad-0055-54da-947d-a0fae04cd079
STIX ID: report--b48095ad-0055-54da-947d-a0fae04cd079
Feed Name: cybersecurityNews.com
CISA warns of a critical SQL injection vulnerability (CVE-2024-43468) in Microsoft Configuration Manager (SCCM) that allows unauthenticated attackers to execute arbitrary SQL queries and potentially OS commands; active exploitation has been reported, the issue was added to CISA’s KEV catalog, and Microsoft published patches (upgrade to 2311 or apply KB5044285 or newer). The advisory urges immediate patching, scanning for suspicious SQL activity, firewall/IIS mitigations, and broader hardening for affected environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
