HomeSecurityCritical vulnerability in Microsoft Entra ID allows full administrative control

Critical vulnerability in Microsoft Entra ID allows full administrative control

A critical vulnerability in Microsoft Entra ID could allow an attacker to gain full administrative control over any tenant in Microsoft's global cloud infrastructure. The bug, which has now been fixed, was discovered in July 2025 and is codenamed CVE-2025-55241.

See also: Microsoft confirms over 900 XSS vulnerabilities in IT services

Microsoft Login ID
Critical vulnerability in Microsoft Entra ID allows full administrative control

The vulnerability in Microsoft Entra ID, described by the researcher as the most significant he will likely ever find, was discovered in a combination of an old authentication mechanism and an API validation error. According to a detailed description by Dirk-jan Mollema, the issue allowed an attacker to use a special type of token from their own tenant to impersonate any user, including Global Administrators, in any other customer tenant.

Actor Tokens are undocumented, internal tokens that Microsoft services use to communicate with each other on behalf of a user. These strong tokens are not subject to standard security policies such as Conditional Access. A critical flaw in the older Azure AD Graph API failed to properly validate that an incoming Actor token came from the same tenant that was being accessed. This validation failure meant that a token requested in an attacker's lab environment could be used to target and access a different organizational tenant.

An attacker could impersonate a Global Admin and gain unrestricted access to modify tenant settings, create or assume identities, and grant any permissions. This control would extend to all connected Microsoft 365, such as Exchange Online and SharePoint Online, as well as any resources hosted in Azure.

See also: Microsoft warns about the end of support for Windows 11 23H2

Critical vulnerability in Microsoft Entra ID allows full administrative control
Critical vulnerability in Microsoft Entra ID allows full administrative control

The nature of the Microsoft Entra ID vulnerability made it extremely dangerous due to its silent operation. The request and use of the malicious tokens produced no logs at all in the victim’s tenant, meaning an attacker could extract sensitive information without leaving a trace. This includes user information and personal data, group and administrative role memberships, tenant settings and security policies, application and Service Principal data, as well as device information and BitLocker recovery keys.

While reading data was silent, modifying objects (such as adding a new administrator) would generate audit logs. However, these files would confusingly show the username of the impersonated administrator but with the display name of a Microsoft service such as “Office 365 Exchange Online,” which could easily be overlooked without specific knowledge of the attack, Dirk-jan Mollema said.

To execute the attack, an adversary would only need the target's public tenant ID and a valid internal user ID (netId). The researcher noted that these netIds could be discovered by brute-force or, more worryingly, by "hopping" between tenants that have a guest user trust (B2B), potentially allowing an exponential spread of the breach across the cloud ecosystem.

The researcher reported the vulnerability to the Microsoft Security Response Center (MSRC) on July 14, 2025, the same day it was discovered. Microsoft acknowledged the severity and deployed a global fix by July 17, 2025. Further mitigations were released in August to prevent applications from requesting these types of Actor tokens for the Azure AD Graph API.

See also: Microsoft avoids EU fine for Teams bundling

Critical vulnerability in Microsoft Entra ID allows full administrative control
Critical vulnerability in Microsoft Entra ID allows full administrative control

According to Microsoft's investigation of its internal telemetry, no evidence of this vulnerability being exploited in the wild has been found. The researcher has provided a Kusto Query Language (KQL) for organizations to look for any potential signs of compromise in their own environments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS