Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file Python exploit POC targeting CVE-2025-55320 in Microsoft SCCM/MECM AdminService. The repository contains one executable script, CVE-2025-55320.py, which combines a custom HTTP NTLM/Negotiate authentication helper with exploit logic for invoking a vulnerable AdminService WMI method. The script builds requests to the HTTPS endpoint /AdminService/wmi/ using the user agent SMS_MP_CONTROL_MANAGER and disables TLS certificate verification. Authentication is handled manually through a requests AuthBase subclass that performs the NTLM challenge/response exchange using impacket SPNEGO/NTLM primitives and supports either plaintext credentials or NTLM hashes. The exploit capability is focused and explicit: it calls the AdminService method SMS_MDMAppleVppToken.SyncToken and injects attacker-controlled SQL through the VppIntuneTokenId argument using the pattern "NULL'); {sql} -- ". This indicates a backend SQL injection primitive in the handling of that method. The operator can supply arbitrary SQL with the -sql argument; by default it uses 'select 1'. The script then prints the JSON response returned by the server. Comments in the code suggest the vulnerable functionality may require the Operations Administrator role. Repository structure is minimal and purpose-built: imports and NTLM auth helper class, SCCMAdmin wrapper for GET/POST request preparation and WMI method invocation, a dedicated exploit method for SMS_MDMAppleVppToken.SyncToken, and a CLI entry point that parses target credentials in impacket style ([domain/][username[:password]@]<address>). This is a real exploit, not a detector, and its maturity is operational rather than weaponized because it provides a working authenticated injection primitive but no broader automation, post-exploitation workflow, or payload framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.