PT-2025-5270 · Microsoft · Intune+1

Comradepurple

·

Published

2025-01-23

·

Updated

2025-01-24

·

CVE-2025-24034

CVSS v3.1

3.2

Low

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Himmelblau versions 0.7.0 through 0.7.14 Himmelblau versions 0.8.0 through 0.8.2
Description Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debug logging is enabled, user access tokens are inadvertently logged, potentially exposing sensitive authentication data. Similarly, Kerberos Ticket-Granting Tickets (TGTs) are logged when debug logging is enabled. Both issues pose a risk of exposing sensitive credentials, particularly in environments where debug logging is enabled.
Recommendations For versions 0.7.0 through 0.7.14, update to version 0.7.15 or later to fix the issue. For versions 0.8.0 through 0.8.2, update to version 0.8.3 or later to fix the issue. As a temporary workaround, disable the logon script option in /etc/himmelblau/himmelblau.conf and avoid using the -d flag when starting the himmelblaud daemon. Disable debug logging globally by setting the debug option in /etc/himmelblau/himmelblau.conf to false and avoiding the -d parameter when starting himmelblaud.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-24034
GHSA-P989-2F5W-9CF6

Affected Products

Intune
Azure Entra Id