---
**CVE-2024-43468**  is a critical-severity vulnerability rated **9.8/10** on the CVSS scale. Microsoft Configuration Manager Remote Code Execution Vulnerability. CISA has confirmed active exploitation in the wild. EPSS estimates a **60.66%** chance of exploitation in the next 30 days.

## Description

**Microsoft Configuration Manager Remote Code Execution Vulnerability**

## Metrics

**CVSS** 3.1 **9.8/10**  
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H  
**EPSS Probability** 60.66%  
99.0th percentile probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Exploitation Status

This vulnerability is listed in CISA’s [Known Exploited Vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) catalog, confirming active exploitation in the wild. Federal agencies must remediate by **Mar 5, 2026**.

## Weakness Enumeration

- [CWE-89](https://cwe.mitre.org/data/definitions/89.html)

## Affected Software

| Vendor       | Product                    | Versions     |
|--------------|----------------------------|--------------|
| Microsoft    | Configuration Manager 2403 | All versions  |
| Microsoft    | Configuration Manager 2409 | All versions  |
| Microsoft    | Configuration Manager 2503 | All versions  |

## References

- [Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468)
- [US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-43468)

## Timeline

**Published**: Oct 8, 2024  
**Last Modified**: Jun 17, 2026  
**Status**: Analyzed

## Frequently Asked Questions

**What is CVE-2024-43468?**

Microsoft Configuration Manager Remote Code Execution Vulnerability

**How severe is CVE-2024-43468?**

CVE-2024-43468 has a CVSS score of **9.8/10** (CRITICAL severity). The EPSS model estimates a **60.66%** probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

**How do I fix CVE-2024-43468?**

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
