None
EN
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
A critical token validation failure in Microsoft Entra ID (previously Azure Active Directory) could have allowed attackers to impersonate any user, including Global Administrators, across any tenant.
It has been described by Microsoft as a privilege escalation flaw in Azure Entra.
Security researcher Dirk-jan Mollema, who discovered and reported the shortcoming on July 14, said the shortcoming made it possible to compromise every Entra ID tenant in the world, with the likely exception of national cloud deployments.
What makes this noteworthy is that the tokens are subject to Microsoft's Conditional Access policies, enabling a bad actor with access to the Graph API to make unauthorized modifications.
"Attackers could craft these [actor] tokens in ways that tricked Entra ID into thinking they were anyone, anywhere," Mitiga's Roei Sherman said.
['impersonation'
'patches'
'global'
'tenant'
'access'
'graph'
'flaw'
'microsoft'
'enabling'
'tenants'
'aws'
'id'
'entra'
'api'
'service'
'critical'
'azure']