Impact
The vulnerability is an improper neutralization of input during web page generation in Microsoft Entra ID, classified as a cross‑site scripting (CWE‑79) flaw. An authorized attacker—an authenticated Entra ID user with permission to influence rendered content—can inject malicious script that runs in Microsoft Edge (Chromium‑based). When executed, the script can create a spoofed user interface over a network, enabling phishing or other spoofing attacks that may lead to credential compromise or unintended authorization.
Affected Systems
Microsoft Edge (Chromium‑based) users who view pages generated by Microsoft Entra ID are impacted. The advisory does not list a specific Edge version range; therefore, any Edge release that renders Entra ID content could be affected. The vulnerability is tied to the Entra ID integration, not to Edge itself.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, reflecting significant impact on confidentiality, integrity, and availability for users who trust the rendered pages. The EPSS score of < 1% suggests a very low exploitation probability, but the flaw is not catalogued in the CISA KEV list. Exploitation requires an authenticated Entra ID account with permission to influence content. An attacker would embed a malicious script that, when rendered by the victim’s Edge browser, performs spoofing or phishing activities, potentially leading to credential compromise or further lateral movement.
OpenCVE Enrichment