You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"[It was discovered that an attacker could] perform actions in Entra ID beyond expected authorization controls, based on analysis of the OAuth 2.0 scope (permissions). Our most concerning discovery involved the ability to add and remove users from privileged roles, including the most powerful role in Entra ID: Global Administrator."
Summary (give a brief description of the issue)
"[It was discovered that an attacker could] perform actions in Entra ID beyond expected authorization controls, based on analysis of the OAuth 2.0 scope (permissions). Our most concerning discovery involved the ability to add and remove users from privileged roles, including the most powerful role in Entra ID: Global Administrator."
References (provide links to blogposts, etc.)
https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
The text was updated successfully, but these errors were encountered: