National Cyber Warfare Foundation (NCWF)

Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants


0 user ratings
2025-09-22 05:56:03
milo
Blue Team (CND)
A critical token validation failure in Microsoft Entra ID (previously Azure Active Directory) could have allowed attackers to impersonate any user, including Global Administrators, across any tenant.
The vulnerability, tracked as CVE-2025-55241, has been assigned the maximum CVSS score of 10.0. It has been described by Microsoft as a privilege escalation flaw in Azure Entra. There is no



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.