← Back to CVE List
Vulnerability Intelligence Report
Microsoft Configuration Manager Spoofing Vulnerability

CVE-2025-59501

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

No Active Exploit Signals
CVSS Base Score
4.8
MEDIUM
Exploitability:1.2
Impact Score:3.6
EPSS Probability:2.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-290 ↗CWE-290: Authentication Bypass by Spoofing

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Microsoft Configuration Manager 1.0.0 < 5.00.9128.1037 (affected)
Microsoft Microsoft Configuration Manager 2409 1.0.0 < 5.00.9132.1031 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.726%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2025-09-17T03:06:33
Published2025-10-31T16:45:40
Patch Date2025-10-24
Last Updated2026-02-22T17:26:16

LINK COPIED TO CLIPBOARD