logo

Arbitrary 1-click Azure tenant takeover via MS application

ID: 44cb40ff-1876-51aa-95fc-d7e49ae8eeb4

STIX ID: report--44cb40ff-1876-51aa-95fc-d7e49ae8eeb4

Feed Name: FalconForce

Threat Score
80/100

Date Published: 2024-04-26

Date Updated: 2026-04-27

Author: Arnau Ortega

...
...

This blog details a critical OAuth redirect/ reply-URL misconfiguration in Azure/Entra ID that allows an attacker who registers or controls an application reply domain to capture authorization codes and exchange them for access tokens — potentially enabling data exfiltration or full tenant takeover. The author demonstrates enumeration scripts, a proof‑of‑concept attack against a Microsoft first‑party app (scv.azureedge.net) that returned tenant-scoped tokens and an operational PoC adding an account to Global Admins, and describes disclosure and remediation steps with Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.