CISA orders urgent patch for actively exploited SCCM flaw

1 min read
Source: BleepingComputer
CISA orders urgent patch for actively exploited SCCM flaw
Photo: BleepingComputer
TL;DR Summary

CISA directed federal agencies to patch CVE-2024-43468, a SQL injection flaw in Microsoft Configuration Manager (SCCM) that is now being actively exploited in attacks. The vulnerability was patched by Microsoft in October 2024, but exploitation was later shown in PoC code, and CISA warns that unpatched systems pose significant risk. Agencies must apply mitigations by March 5 under BOD 22-01, and CISA recommends that organizations outside federal use vendor guidance to secure affected systems as soon as possible.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

3 min

vs 4 min read

Condensed

88%

64478 words

Want the full story? Read the original article

Read on BleepingComputer