Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a focused Python proof-of-concept/operational exploit for CVE-2025-59213, an unauthenticated SQL injection in Microsoft Configuration Manager (SCCM/ConfigMgr) Discovery Data Manager. The repo is minimal: one main exploit script (CVE-2025-59213.py), a README with vulnerability/usage details, and a requirements file listing requests and cryptography. The exploit is not part of a larger framework. Its main capability is to execute arbitrary attacker-controlled SQL queries against the SCCM site database by abusing the client registration workflow and triggering a duplicate hardware-ID merge condition in DDM. The script appears to automate the full attack chain: generating or loading cryptographic material, creating SCCM-compatible certificates/signatures, registering two fake clients, waiting for registration propagation, sending a crafted DDR report that carries the SQL injection in the Hardware_ID0-related path, and optionally cleaning up the created clients afterward. Code structure indicates helper time-formatting functions, a CryptoTools class for RSA key generation, certificate creation, SCCM-specific public key blob formatting, signing, and PEM import/export, and an SCCM class that builds multipart/CCM XML messages and drives the registration/exploitation workflow. The command-line interface exposes target URL, optional mTLS key/cert, optional signing key, alternate authentication mode, SQL payload, verbosity, client name, registration delay, and cleanup control. Operationally, this is a network/web-targeted exploit against an SCCM Management Point. It supports environments where HTTPS-only mode requires client certificates, but also documents an alternate authentication endpoint option. The payload is not a shell; instead it is arbitrary SQL supplied by the operator via -sql. Because the README notes the injection is asynchronous, the exploit is intended for blind or indirect SQL execution rather than immediate response-based extraction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.