Movatterモバイル変換


[0]ホーム

URL:


Sign in / up
The Register

Security

One token to pwn them all: Entra ID bug could have granted access to every tenant

Until Microsoft lobbed it into a virtual volcano

iconRichard Speed
Fri 19 Sep 2025 //12:30 UTC

A security researcher claims to have found a flaw that could have handed him the keys to almost every Entra ID tenant worldwide.

Dirk-jan Mollema reported the finding to the Microsoft Security Research Center (MSRC) in July. The issue was fixed and confirmed as mitigated, and aCVE was raised on September 4.

It is, however, an alarming vulnerability involving flawed token validation that can result in cross-tenant access. "If you are an Entra ID admin," wrote Mollema, "that means complete access to your tenant."

There are two main elements in the vulnerability. The first, according to Mollema, is undocumented impersonation tokens called "Actor tokens" that Microsoft uses for service-to-service communication. There was a flaw in the legacy Azure Active Directory Graph API that did not properly validate the originating tenant, allowing the tokens to be used for cross-tenant access.

"Effectively," wrote Mollema, "this means that with a token I requested in my lab tenant I could authenticate as any user, including Global Admins, in any other tenant."

The tokens allowed full access to the Azure AD Graph API in any tenant. Any hope that a log might save the day was also dashed – "requesting Actor tokens does not generate logs."

"Even if it did, they would be generated in my tenant instead of in the victim tenant, which means there is no record of the existence of these tokens."

The upshot of the flaw was a possible compromise for any service that uses Entra ID for authentication, such as SharePoint Online or Exchange Online. Mollema noted that access to resources hosted in Azure was also possible.

Microsoft's swiftness in resolving the issue is to be commended, even if it's unfortunate that it was present in the first place. Additionally, Mollema noted that Microsoft had not detected any abuse of the vulnerability in its internal telemetry.

That said, the researcher has provided some KQL for worried admins to use for tracking down evidence of possible abuse.

Mollemacalled this "the most impactful vulnerability I will probably ever find," and it is difficult to dispute the claim. The CVE for the issue rates it as "Critical" with a "Low" Attack Complexity metric. The base score is 10.

To reiterate, according to Microsoft, the vulnerability has been fully mitigated, and users do not need to take any further action.

Still, before the vulnerability was found, there existed, in Mollema's words, "one token to rule them all." ®


More like these

More about


COMMENTS

More about

More like these

TIP US OFF

Send us news


Other stories you might like

Microsoft kills 9.9-rated ASP.NET Core bug – 'our highest ever' score

Flaw in Kestrel web server allowed request smuggling, impact depends on hosting setup and application code
Security16 Oct 2025 |3

The real insight behind measuring Copilot usage is Microsoft's desperation

Opinion Citizen! You are falling short in your AI usage targets! Strive harder for the revolution!
AI + ML20 Oct 2025 |58

£2B UK cloud licensing claim against Microsoft seeks more business backers

Updated Action alleges Redmond unfairly hikes costs for businesses running Windows Server outside Azure
Software15 Oct 2025 |5

Built for what's next: Arm's advantage in the AI PC era

When considering your upgrade for Windows 11, it’s time to look at Arm vs x86 - It's an upgrade to improved efficiency, performance, and battery life.
Sponsored Feature

Feeling lonely? Microsoft Copilot can now listen to your every word, watch your screen

We've seen this before and it was called Cortana or Clippy
AI + ML16 Oct 2025 |52

Microsoft seeding Washington schools with free AI to get kids and teachers hooked

To the slop trough, kiddos!
AI + ML14 Oct 2025 |18

Microsoft hypes PCs with NPUs, still can't offer a good reason to buy one

Comment AI tech not on the hardware compatibility list for now. But future Windows will need it
AI + ML10 Oct 2025 |31

Microsoft 'illegally' tracked students via 365 Education, says data watchdog

Redmond argued schools, education authorities are responsible for GDPR
SaaS13 Oct 2025 |25

Tribunal wonders if Microsoft has found a legal hero after pivot to copyright gambit

ValueLicensing dispute probes whether Office counts as a creative work
Software20 Oct 2025 |19

Microsoft lets bosses spot teams that are dodging Copilot

Viva Insights turns AI guzzling into a leaderboard
AI + ML10 Oct 2025 |80

What do we want? Windows 10 support! When do we want it? Until 2030!

Updated Protesters slam forced obsolescence outside Microsoft's office
OSes14 Oct 2025 |71

Shadow AI: Staffers are bringing AI tools they use at home to work, warns Microsoft

Bring Your Copilot To Work Day, anyone?
AI + ML14 Oct 2025 |30

[8]ページ先頭

©2009-2025 Movatter.jp