Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • How to Shop Like a Pro During Amazon Prime Day (2026)
    • CFTC seeks injunction in Kalshi Rhode Island dispute
    • As AI Expands, Erin Brockovich Taps Communities to Map Data Center Concerns
    • Direct-to-Cell Technology: Enabling Satellite Connectivity for Legacy Devices
    • How small businesses can leverage AI
    • Robots-Blog | Humanoide Robotik aus Deutschland: igus bringt neuen Serviceroboter auf den Markt
    • GM reimagines Hummer off-roader with California ideas unit
    • London’s DEScycle secures over €10 million in grant funding to scale critical metals recovery platform
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»Technology»This Microsoft Entra ID Vulnerability Could Have Been Catastrophic
    Technology

    This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

    Editor Times FeaturedBy Editor Times FeaturedSeptember 18, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    As companies round the world have shifted their digital infrastructure over the past decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in safety features of main cloud suppliers like Microsoft. However with a lot using on these methods, there might be probably disastrous consequences at an enormous scale if one thing goes flawed. Living proof: Safety researcher Dirk-jan Mollema just lately stumbled upon a pair of vulnerabilities in Microsoft Azure’s identification and entry administration platform that might have been exploited for a probably cataclysmic takeover of all Azure buyer accounts.

    Generally known as Entra ID, the system shops every Azure cloud buyer’s consumer identities, sign-in entry controls, functions, and subscription administration instruments. Mollema has studied Entra ID safety in depth and printed a number of research about weaknesses within the system, which was previously often known as Azure Lively Listing. However whereas getting ready to present on the Black Hat safety convention in Las Vegas in July, Mollema found two vulnerabilities that he realized may very well be used to achieve international administrator privileges—primarily god mode—and compromise each Entra ID listing, or what is called a “tenant.” Mollema says that this might have uncovered almost each Entra ID tenant on the earth apart from, maybe, authorities cloud infrastructure.

    “I used to be simply observing my display screen. I used to be like, ‘No, this shouldn’’t actually occur,’” says Mollema, who runs the Dutch cybersecurity firm Outsider Safety and makes a speciality of cloud safety. “It was fairly dangerous. As dangerous because it will get, I’d say.”

    “From my very own tenants—my take a look at tenant or perhaps a trial tenant—you could possibly request these tokens and you could possibly impersonate principally anyone else in anyone else’s tenant,” Mollema provides. “Which means you could possibly modify different folks’s configuration, create new and admin customers in that tenant, and do something you desire to.”

    Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Safety Response Middle on July 14, the identical day that he found the issues. Microsoft began investigating the findings that day and issued a repair globally on July 17. The corporate confirmed to Mollema that the problem was fastened by July 23 and applied additional measures in August. Microsoft issued a CVE for the vulnerability on September 4.

    “We mitigated the newly recognized difficulty rapidly, and accelerated the remediation work underway to decommission this legacy protocol utilization, as a part of our Safe Future Initiative,” Tom Gallagher, Microsoft’s Safety Response Middle vp of engineering, informed WIRED in a press release. “We applied a code change inside the susceptible validation logic, examined the repair, and utilized it throughout our cloud ecosystem.”

    Gallagher says that Microsoft discovered “no proof of abuse” of the vulnerability throughout its investigation.

    Each vulnerabilities relate to legacy methods nonetheless functioning inside Entra ID. The primary includes a sort of Azure authentication token Mollema found often known as Actor Tokens which are issued by an obscure Azure mechanism referred to as the “Entry Management Service.” Actor Tokens have some particular system properties that Mollema realized may very well be helpful to an attacker when mixed with one other vulnerability. The opposite bug was a serious flaw in a historic Azure Lively Listing software programming interface often known as “Graph” that was used to facilitate entry to information saved in Microsoft 365. Microsoft is within the strategy of retiring Azure Lively Listing Graph and transitioning customers to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was associated to a failure by Azure AD Graph to correctly validate which Azure tenant was making an entry request, which may very well be manipulated so the API would settle for an Actor Token from a distinct tenant that ought to have been rejected.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    How to Shop Like a Pro During Amazon Prime Day (2026)

    June 2, 2026

    How to Edit, Merge, and Split PDFs With Free Online Tools

    June 2, 2026

    Whoop Promo Codes May 2026: 20% Off | June 2026

    June 2, 2026

    Websites Can Now Spy on You Through Your Hard Drive

    June 2, 2026

    ‘Sexual Chocolate’ Faces Recalls After FDA Tests Reveal Undisclosed Viagra

    June 2, 2026

    Norse Atlantic Airways Offers Dirt-Cheap Tickets. There’s a Catch

    June 1, 2026

    Comments are closed.

    Editors Picks

    How to Shop Like a Pro During Amazon Prime Day (2026)

    June 2, 2026

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    As AI Expands, Erin Brockovich Taps Communities to Map Data Center Concerns

    June 2, 2026

    Direct-to-Cell Technology: Enabling Satellite Connectivity for Legacy Devices

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    I Learned Every Photographer Needs These 3 Types of Cameras

    November 28, 2025

    Americans are expected to spend $30 billion betting on the upcoming NFL season

    August 30, 2025

    CFTC backs Kalshi against state gambling enforcement

    May 13, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.