Impact
An attacker can exploit an authentication bypass that uses an alternate path or channel within Microsoft Entra ID to gain higher privileges over a network, enabling unauthorized access to resources or services protected by the directory. This weakness, classified as CWE-288, permits an attacker to elevate privileges without needing valid credentials, potentially compromising confidentiality, integrity, or availability of the affected services.
Affected Systems
Microsoft Entra ID is impacted. No specific version information is provided, so all current releases should be reviewed for the applied fix.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1, indicating a high severity critical risk. An EPSS score is not available, and it is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be a network-based authentication bypass, enabling privilege escalation without privilege chaining or arbitrary code execution.
OpenCVE Enrichment