This Microsoft Entra ID Vulnerability Could Have Been Catastrophic
ID: d6d401b3-2313-5ba2-a93c-4eb4d6ed9e6d
STIX ID: report--d6d401b3-2313-5ba2-a93c-4eb4d6ed9e6d
Feed Name: WIRED Security
Threat Score
Security researcher Dirk-jan Mollema discovered two vulnerabilities in Microsoft Entra ID that could be used to request actor tokens capable of impersonating users across tenants and thereby obtain Global Administrator privileges across nearly all Entra ID tenants; he disclosed the issues to Microsoft, which fixed the validation logic within days and later issued CVE-2025-55241.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
