CVE-2025-59501: Microsoft Configuration Manager 2403

Medium severity, CVSS 4.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

Affected products

  • Microsoft Configuration Manager 2403: before 5.00.9128.1037 (fixed in 5.00.9128.1037)
  • Microsoft Configuration Manager 2409: before 5.00.9132.1031 (fixed in 5.00.9132.1031)
  • Microsoft Configuration Manager 2503: before 5.0.9135.1013 (fixed in 5.0.9135.1013)

Published 2025-10-31. Last modified 2026-06-17.