CVE-2025-47179: Microsoft Configuration Manager 2403

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Configuration Manager 2403: before 5.00.9128.1037 (fixed in 5.00.9128.1037)
  • Microsoft Configuration Manager 2409: before 5.00.9132.1031 (fixed in 5.00.9132.1031)
  • Microsoft Configuration Manager 2503: before 5.0.9135.1013 (fixed in 5.0.9135.1013)

Published 2025-11-11. Last modified 2026-06-17.