PT-2025-41481 · Microsoft · Azure Entra Id

Vladimir Abramzon

·

Published

2025-10-09

·

Updated

2026-02-04

·

CVE-2025-59218

CVSS v3.1

9.7

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Azure Entra ID (affected versions not specified)
Description An elevation of privilege issue exists in Azure Entra ID. This allows unauthorized access and potential compromise of accounts. Details regarding the technical aspects of exploitation, such as specific API endpoints or vulnerable parameters, are not available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-12828
CVE-2025-59218

Affected Products

Azure Entra Id