CVE-2025-59501: Microsoft Configuration Manager 2403
Medium severity, CVSS 4.8. EPSS: 3.3% chance of exploitation in the next 30 days.
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.
Affected products
- Microsoft Configuration Manager 2403: before 5.00.9128.1037 (fixed in 5.00.9128.1037)
- Microsoft Configuration Manager 2409: before 5.00.9132.1031 (fixed in 5.00.9132.1031)
- Microsoft Configuration Manager 2503: before 5.0.9135.1013 (fixed in 5.0.9135.1013)
Published 2025-10-31. Last modified 2026-06-17.