Close Menu
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
Trending

India’s Confidence Crisis Curbs Financial Engagement Despite High Access

March 24, 2026

Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

March 24, 2026

March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

March 24, 2026

Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

March 24, 2026

Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

March 24, 2026

Claude AI Now Executes Tasks Directly on macOS Devices

March 24, 2026

Trump Halts Iran Strikes for 5 Days Amid Talk Claims

March 24, 2026
Facebook X (Twitter) Instagram
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
VernoNews
Home»Technology»This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now
Technology

This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now

VernoNewsBy VernoNewsSeptember 22, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
This critical Microsoft Entra flaw may have let hackers infiltrate any consumer, so patch now
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

[ad_1]


  • Actor tokens allowed cross-tenant impersonation with out logging or safety checks
  • CVE-2025-55241 enabled International Admin entry through deprecated Azure AD Graph API
  • Microsoft patched the flaw in September 2025; actor tokens and Graph API are being phased out

Safety researchers have discovered a vital vulnerability in Microsoft Entra ID which may have allowed risk actors to achieve International Administrator entry to nearly anybody’s tenant – with out being detected in any approach.

The vulnerability consists of two issues – a legacy service known as “actor tokens”, and a vital Elevation of Privilege bug tracked as CVE-2025-55241.

Actor tokens are undocumented, unsigned authentication tokens utilized in Microsoft providers to impersonate customers throughout tenants. They’re issued by a legacy system known as Entry Management Service (ACS) and have been initially designed for service-to-service (S2S) authentication.


It’s possible you’ll like

Deprecating and phasing out

Based on safety researcher Dirk-jan Mollema who found the flaw, these tokens bypass commonplace safety controls, lack logging, and stay legitimate for twenty-four hours, which makes them exploitable for unauthorized entry with out detection.

Mollema demonstrated that by crafting impersonation tokens utilizing public tenant IDs and consumer identifiers, he may entry delicate knowledge and carry out administrative actions in different organizations’ environments.

These actions included creating customers, resetting passwords, and modifying configurations – all with out producing logs within the sufferer tenant.

“I examined this in just a few extra take a look at tenants I had entry to, to ensure I used to be not loopy, however I may certainly entry knowledge in different tenants, so long as I knew their tenant ID (which is public data) and the netId of a consumer in that tenant,” Mollema defined.

Signal as much as the TechRadar Professional e-newsletter to get all the highest information, opinion, options and steering your online business must succeed!

Because it seems, Azure AD Graph API, a deprecated system that’s slowly being phased out, was accepting the tokens from one tenant and making use of them to a different, bypassing conditional entry insurance policies and commonplace authentication checks.

Mollema reported the problem on Microsoft, which acknowledged it in mid-July 2025, and patched inside two weeks. CVE-2025-55241 was given a severity rating of 10/10 (vital), and was formally addressed on September 4.

Azure AD Graph API is being deprecated, whereas the tokens, which Microsoft refers to as “high-privileged entry” mechanisms used internally, are being phased out.

By way of BleepingComputer

You may additionally like

[ad_2]

Avatar photo
VernoNews

    Related Posts

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    iPhone Air C1X Modem Matches Qualcomm X80, Leads in 5G Latency

    March 23, 2026

    5 GEO Strategies to Boost Brand Visibility in AI Search 2026

    March 23, 2026
    Leave A Reply Cancel Reply

    Don't Miss
    Business

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    By VernoNewsMarch 24, 20260

    India’s financial sector provides widespread access to products, yet a confidence crisis among consumers hampers…

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    Trump Halts Iran Strikes for 5 Days Amid Talk Claims

    March 24, 2026
    About Us
    About Us

    VernoNews delivers fast, fearless coverage of the stories that matter — from breaking news and politics to pop culture and tech. Stay informed, stay sharp, stay ahead with VernoNews.

    Our Picks

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    March 24, 2026

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026
    Trending

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026
    • Contact Us
    • Privacy Policy
    • Terms of Service
    2025 Copyright © VernoNews. All rights reserved

    Type above and press Enter to search. Press Esc to cancel.