Impact
Azure Entra ID contains a data validation weakness (CWE-345) where data authenticity is not fully verified, allowing an authorized attacker to forge identity information over a network. This can lead to impersonation of legitimate users, unauthorized access, and potential escalation of privileges. The vulnerability directly affects the confidentiality and integrity of authentication processes.
Affected Systems
The affected product is Microsoft Azure Entra ID, provided by Microsoft Entra. No specific version information is supplied, so all instances of Azure Entra ID deployed by an organization should be treated as potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not in widespread use yet. Based on the description, the likely attack vector is a network‑based spoofing attempt from an authenticated attacker, meaning the risk is higher for organizations with privileged or internal users.
OpenCVE Enrichment