CVE-2025-59501

MEDIUM

Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-59501. PoCs published by garrettfoster13, adminlove520.

AI-analyzed exploit summary This PoC exploits CVE-2025-59501 by abusing SCCM's AdminService API with Entra ID integration to elevate privileges to Full Administrator. It consists of two modules: one for obtaining an access token via MSAL and another for adding a user as an SCCM admin via the AdminService API.

Description

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

Exploits (2)

nomisec WORKING POC 25 stars
by garrettfoster13 · poc
https://github.com/garrettfoster13/CVE-2025-59501

This PoC exploits CVE-2025-59501 by abusing SCCM's AdminService API with Entra ID integration to elevate privileges to Full Administrator. It consists of two modules: one for obtaining an access token via MSAL and another for adding a user as an SCCM admin via the AdminService API.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft System Center Configuration Manager (SCCM) with Entra ID integration
Auth required
Prerequisites: Valid Entra ID credentials · Azure app client ID · Tenant ID · Target SMS provider FQDN/IP · Target user SID
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-59501

This repository contains a functional exploit PoC for CVE-2025-59501, which abuses SCCM's AdminService API when Entra ID integration is enabled to elevate privileges to Full Administrator. The exploit consists of two modules: one for obtaining an access token and another for adding a user as an SCCM admin.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft System Center Configuration Manager (SCCM) with Entra ID integration
Auth required
Prerequisites: Valid Entra ID credentials · Azure app client ID · Tenant ID · Target SMS provider FQDN/IP · User SID
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0287
EPSS Percentile 84.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (3)
microsoft/configuration_manager_2403 < 5.00.9128.1037
microsoft/configuration_manager_2409 < 5.00.9132.1031
microsoft/configuration_manager_2503 < 5.0.9135.1013
Published Oct 31, 2025
Tracked Since Feb 18, 2026