Close Menu
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
Trending

Egypt’s president pardons British-Egyptian activist Alaa Abdel Fattah

September 22, 2025

Shares Sag As Final Full Buying and selling Week of Third Quarter Kicks Off

September 22, 2025

How To Optimize For Featured Snippets And AI Overviews

September 22, 2025

Lais Ribeiro Stuns In Unique Trend Shoot For Brazilian Journal

September 22, 2025

Erika Forgives Murderer, Trump Notes Announcement

September 22, 2025

Gabriella Reyes and Duke Kim Bridge Disciplines in ‘West Aspect Story’

September 22, 2025

Might new comet C/2025 R2 (SWAN) turn into seen to the bare eye in October? Here is what we all know

September 22, 2025
Facebook X (Twitter) Instagram
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
VernoNews
Home»Technology»This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now
Technology

This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now

VernoNewsBy VernoNewsSeptember 22, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email




  • Actor tokens allowed cross-tenant impersonation with out logging or safety checks
  • CVE-2025-55241 enabled International Admin entry through deprecated Azure AD Graph API
  • Microsoft patched the flaw in September 2025; actor tokens and Graph API are being phased out

Safety researchers have discovered a vital vulnerability in Microsoft Entra ID which may have allowed risk actors to achieve International Administrator entry to nearly anybody’s tenant – with out being detected in any approach.

The vulnerability consists of two issues – a legacy service known as “actor tokens”, and a vital Elevation of Privilege bug tracked as CVE-2025-55241.

Actor tokens are undocumented, unsigned authentication tokens utilized in Microsoft providers to impersonate customers throughout tenants. They’re issued by a legacy system known as Entry Management Service (ACS) and have been initially designed for service-to-service (S2S) authentication.


It’s possible you’ll like

Deprecating and phasing out

Based on safety researcher Dirk-jan Mollema who found the flaw, these tokens bypass commonplace safety controls, lack logging, and stay legitimate for twenty-four hours, which makes them exploitable for unauthorized entry with out detection.

Mollema demonstrated that by crafting impersonation tokens utilizing public tenant IDs and consumer identifiers, he may entry delicate knowledge and carry out administrative actions in different organizations’ environments.

These actions included creating customers, resetting passwords, and modifying configurations – all with out producing logs within the sufferer tenant.

“I examined this in just a few extra take a look at tenants I had entry to, to ensure I used to be not loopy, however I may certainly entry knowledge in different tenants, so long as I knew their tenant ID (which is public data) and the netId of a consumer in that tenant,” Mollema defined.

Signal as much as the TechRadar Professional e-newsletter to get all the highest information, opinion, options and steering your online business must succeed!

Because it seems, Azure AD Graph API, a deprecated system that’s slowly being phased out, was accepting the tokens from one tenant and making use of them to a different, bypassing conditional entry insurance policies and commonplace authentication checks.

Mollema reported the problem on Microsoft, which acknowledged it in mid-July 2025, and patched inside two weeks. CVE-2025-55241 was given a severity rating of 10/10 (vital), and was formally addressed on September 4.

Azure AD Graph API is being deprecated, whereas the tokens, which Microsoft refers to as “high-privileged entry” mechanisms used internally, are being phased out.

By way of BleepingComputer

You may additionally like

Avatar photo
VernoNews

Related Posts

Ought to You Subscribe to Garmin Join+? (2025)

September 22, 2025

Greatest Fitbit deal: Save $50 on Fitbit Sense 2 at Amazon

September 22, 2025

Finest Sheets for Each Mattress and Funds (2025): Cotton, Linen, Bamboo

September 22, 2025
Leave A Reply Cancel Reply

Don't Miss
World

Egypt’s president pardons British-Egyptian activist Alaa Abdel Fattah

By VernoNewsSeptember 22, 20250

Egypt’s President Abdul Fattah al-Sisi has pardoned the outstanding British-Egyptian activist Alaa Abdel Fattah, who…

Shares Sag As Final Full Buying and selling Week of Third Quarter Kicks Off

September 22, 2025

How To Optimize For Featured Snippets And AI Overviews

September 22, 2025

Lais Ribeiro Stuns In Unique Trend Shoot For Brazilian Journal

September 22, 2025

Erika Forgives Murderer, Trump Notes Announcement

September 22, 2025

Gabriella Reyes and Duke Kim Bridge Disciplines in ‘West Aspect Story’

September 22, 2025

Might new comet C/2025 R2 (SWAN) turn into seen to the bare eye in October? Here is what we all know

September 22, 2025
About Us
About Us

VernoNews delivers fast, fearless coverage of the stories that matter — from breaking news and politics to pop culture and tech. Stay informed, stay sharp, stay ahead with VernoNews.

Our Picks

Egypt’s president pardons British-Egyptian activist Alaa Abdel Fattah

September 22, 2025

Shares Sag As Final Full Buying and selling Week of Third Quarter Kicks Off

September 22, 2025

How To Optimize For Featured Snippets And AI Overviews

September 22, 2025
Trending

Lais Ribeiro Stuns In Unique Trend Shoot For Brazilian Journal

September 22, 2025

Erika Forgives Murderer, Trump Notes Announcement

September 22, 2025

Gabriella Reyes and Duke Kim Bridge Disciplines in ‘West Aspect Story’

September 22, 2025
  • Contact Us
  • Privacy Policy
  • Terms of Service
2025 Copyright © VernoNews. All rights reserved

Type above and press Enter to search. Press Esc to cancel.