Azure Entra Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55241
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
https://www.bleepingcomputer.com/news/security/microsoft-entra-id-flaw-allowed-hijacking-any-companys-tenant/
https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html
https://www.darkreading.com/cloud-security/critical-azure-entra-id-flaw-microsoft-iam-issues
Source: Mitre, NVD
Published: 2025-09-04
Updated: 2025-09-18
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.00081