PT-2025-31706 · Microsoft · Himmelblau+2

Carlesgs

·

Published

2025-08-01

·

Updated

2025-08-02

·

CVE-2025-54781

CVSS v3.1

2.8

Low

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Himmelblau version 1.0.0 versions prior to 1.1.0
Description Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau, the himmelblaud tasks service leaks an Intune service access token to the system journal. This token can be used to detect the host's Intune compliance status and may permit additional administrative operations for the Intune host device.
Recommendations Ensure that Himmelblau debugging is disabled for version 1.0.0. Update to version 1.1.0 or later.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-54781
GHSA-78QG-VMRW-574W

Affected Products

Himmelblau
Intune
Azure Entra Id