CVE-2025-59501
MEDIUMMicrosoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
Title source: ruleExploitation Summary
EIP tracks 2 public exploits for CVE-2025-59501. PoCs published by garrettfoster13, adminlove520.
AI-analyzed exploit summary This PoC exploits CVE-2025-59501 by abusing SCCM's AdminService API with Entra ID integration to elevate privileges to Full Administrator. It consists of two modules: one for obtaining an access token via MSAL and another for adding a user as an SCCM admin via the AdminService API.
Description
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.
Exploits (2)
This PoC exploits CVE-2025-59501 by abusing SCCM's AdminService API with Entra ID integration to elevate privileges to Full Administrator. It consists of two modules: one for obtaining an access token via MSAL and another for adding a user as an SCCM admin via the AdminService API.
This repository contains a functional exploit PoC for CVE-2025-59501, which abuses SCCM's AdminService API when Entra ID integration is enabled to elevate privileges to Full Administrator. The exploit consists of two modules: one for obtaining an access token and another for adding a user as an SCCM admin.
References (1)
Scores
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N