PT-2025-36098 · Microsoft · Azure Entra
Dirk-Jan Mollema
+1
·
Published
2025-09-04
·
Updated
2026-02-09
·
CVE-2025-55241
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Entra ID (formerly Azure Active Directory) (affected versions not specified)
Description
A critical flaw in Microsoft Entra ID, stemming from undocumented “Actor tokens” and a vulnerability in the Azure AD Graph API, could have allowed attackers to impersonate any user, including Global Administrators, across any tenant. This vulnerability, tracked as CVE-2025-55241, had a CVSS score of 10.0 and allowed for cross-tenant access without triggering security alerts. The issue arose from a lack of proper tenant validation, enabling attackers with a token from one tenant to gain control over others. The vulnerability was patched in July 2025, and there have been no reported exploits as of September 2025. The flaw highlights the risks associated with legacy APIs and centralized identity management systems.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11135
CVE-2025-55241
Affected Products
Azure Entra
References · 97
- 🔥 https://github.com/Spanky-McSpank/CVE-2025-55241-Internal-Audit · Exploit
- 🔥 https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens · Exploit
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55241 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-55241 · Security Note
- https://bdu.fstec.ru/vul/2025-11135 · Security Note
- https://twitter.com/QuestJAS/status/1978817792271962306 · Twitter Post
- https://reddit.com/r/fefe_blog_interim/comments/1nkdtsd/microsoft_entra_id_aka_azure_active_directory · Reddit Post
- https://twitter.com/grok/status/2020787042855026998 · Twitter Post
- https://reddit.com/r/KibernetinisSaugumas/comments/1nm0e3z/kritinis_azure_entra_id_pa%C5%BEeid%C5%BEiamumas · Reddit Post
- https://twitter.com/securestep9/status/1968439977835987038 · Twitter Post
- https://twitter.com/dailytechonx/status/1968766982112604382 · Twitter Post
- https://twitter.com/BhuvaneswariM15/status/1970255935655551150 · Twitter Post
- https://twitter.com/grok/status/1970915393452794249 · Twitter Post
- https://twitter.com/cyashadotcom/status/1970371176527761604 · Twitter Post
- https://twitter.com/ElwaliKarkoub/status/1969165805146308733 · Twitter Post