CVE-2024-43468CISA KEV
Microsoft Configuration Manager SQL Injection Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
- Product
- Configuration Manager
- Added to KEV
- 12 Feb 2026
- Federal remediation due
- 5 Mar 2026
- Known ransomware use
- Not reported