Impact
Untrusted data is deserialized by Microsoft Entra ID without adequate validation, enabling an attacker to inject malicious object data that is executed upon processing. The flaw is a classic deserialization vulnerability (CWE‑502). The outcome is that any code supplied by the attacker can run with the privileges of the Entra ID process, potentially compromising user accounts, data, or the entire identity platform. The description indicates a direct code execution impact with no mention of limited scope or restrictions.
Affected Systems
Microsoft Entra ID, a Microsoft product used for identity and access management. The exact affected versions are not listed in the data provided, so any installation of Microsoft Entra ID without a recent update should be considered vulnerable until proven otherwise.
Risk and Exploitability
The CVSS score of 10 underscores a critical severity, and the EPSS score of 1% indicates a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver malicious serialized data to an Entra ID endpoint over the network; the description suggests a remote, network‑based vector. Since no mitigation steps from Microsoft are specified in the entry, the risk remains high pending a vendor patch.
OpenCVE Enrichment