Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html
ONE SENTENCE SUMMARY:
A critical vulnerability in Microsoft Entra ID could allow attackers to impersonate users across tenants, granting access to sensitive resources.
MAIN POINTS:
- Vulnerability CVE-2025-55241 allows cross-tenant impersonation in Microsoft Entra ID.
- It’s rated a maximum CVSS score of 10.0, highlighting its severity.
- Discovered by Dirk-jan Mollema, it affects all tenants except national clouds.
- Exploit involves flawed validation in the Azure AD Graph API.
- Exploitation bypasses MFA, Conditional Access, and leaves no traces.
- Global Admin impersonation could lead to full tenant compromise.
- The legacy API responsible is officially deprecated as of August 2025.
- Similar vulnerabilities in Exchange Server and cloud services were also disclosed.
- API Connections facilitate cross-tenant access to backend resources.
- Misconfigurations can lead to widespread data theft and follow-on attacks.
TAKEAWAYS:
- Critical flaws in legacy APIs can lead to severe security breaches.
- Cross-tenant access allows impersonation of high-privilege roles like Global Admins.
- Deprecated services like Azure AD Graph must be urgently replaced.
- Security depends on thorough validation and monitoring of access points.
- Misconfigurations in cloud environments pose ongoing risks to data security.