CVE-2025-47179: Microsoft Configuration Manager 2403
Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Configuration Manager 2403: before 5.00.9128.1037 (fixed in 5.00.9128.1037)
- Microsoft Configuration Manager 2409: before 5.00.9132.1031 (fixed in 5.00.9132.1031)
- Microsoft Configuration Manager 2503: before 5.0.9135.1013 (fixed in 5.0.9135.1013)
Published 2025-11-11. Last modified 2026-06-17.