CVE-2025-59501

Published Oct 31, 2025

Last updated a month ago

CVSS medium 4.8
Microsoft Configuration Manager

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-59501 is an authentication bypass vulnerability affecting Microsoft Configuration Manager. It allows an authorized attacker to perform spoofing over an adjacent network. The vulnerability can be exploited by modifying the User Principal Name (UPN) of a valid Microsoft Entra ID account or by creating a new account to impersonate an Active Directory user with the same UPN that was not synchronized to Entra ID. Successful exploitation could allow an attacker to gain unauthorized administrative control over Microsoft Configuration Manager and its managed clients.

Description
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
configuration_manager_2403, configuration_manager_2409, configuration_manager_2503

Risk scores

CVSS 3.1

Type
Primary
Base score
4.8
Impact score
3.6
Exploitability score
1.2
Vector string
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-290

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.