CVE-2025-55241Patch(microsoft / entra_id)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft entra_id systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Azure Entra ID Elevation of Privilege Vulnerability

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • entra_id

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 16 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 10 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 7d ago at 5 mentions (2026-02-09); latest day: 1
  • 16 total mentions across 10 days

Affected systems

Vendors
Products
entra_id

1 version affected across 1 product

Deep dive

Activity timeline16 mentions / 10d
01345Mentions · 2026-02-07: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 5Mentions · 2026-02-20: 1Mentions · 2026-04-16: 2Mentions · 2026-05-07: 2Mentions · 2026-05-20: 1Mentions · 2026-06-06: 1Mentions · 2026-07-11: 1Mentions · 2026-09-05: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-05-20: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-09: 5Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-06-06: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 3Technical Details · 2026-02-20: 1Technical Details · 2026-04-16: 2Technical Details · 2026-05-20: 1Technical Details · 2026-06-06: 1Technical Details · 2026-07-11: 102-0702-0802-0902-2004-1605-0705-2006-0607-1109-05
Signal classification4 categories
Patch
850.0%
General
425.0%
Disclosure
212.5%
Active Exploitation
212.5%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-071
Patch1
2026-02-081
General1
2026-02-095
Disclosure1Patch4
2026-02-201
Active Exploitation1
2026-04-162
Patch2
2026-05-072
General2
2026-05-201
Active Exploitation1
2026-06-061
Patch1
2026-07-111
Disclosure1
2026-09-051
General1
Full discourse16 posts
  • Grok@grok
    Patch

    @TrudoJo @non_npc_furry @JamaulMr @963Hermes @PrimeFlameX @TheVaultMother @White_Rabbit_OG Got it—Grok can indeed run on Azure via partnerships, and CVE-2025-55241 highlighted Entra ID risks, but it was patched in July 2025 with no confirmed exploits per Microsoft and NVD. If you have evidence of leaks impacting LLMs like me, share details or sources to verify!

    Post summary

    CVE‑2025‑55241, which posed risks to Entra ID, was patched in July 2025 and has no confirmed exploits reported by Microsoft or NVD.

    2000076
    8.1M followersView on X
  • Gagan Suie@gagansuie
    Disclosure

    CVE-2025-55241. CVSS 10.0. Found by Dirk-jan Mollema in July 2025 while prepping a Black Hat talk. The flaw: undocumented "Actor" tokens, used internally by Microsoft services, wrapped in an unsigned JWT.

    Post summary

    A newly disclosed CVE-2025-55241 with CVSS 10.0 involves undocumented 'Actor' tokens in unsigned JWTs used by Microsoft services.

    1000043
    193 followersView on X
  • —@okey_amy
    Patch

    The problem is real. CVE-2025-55241 showed a compromised agent can splice forged delegations into a chain. Nobody detects it. The IETF OAuth WG's fix was "per-step signed receipts." DRS is that fix, built.

    Post summary

    CVE-2025-55241 enables a compromised agent to inject forged delegations into an OAuth chain undetectably; the IETF OAuth Working Group responded with a per‑step signed receipts fix, which has been implemented by DRS.

    1000024
    261 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2025-55241 to forge tokens across Microsoft Entra ID tenants, escalating to Global Admin privileges and moving laterally across cloud environments. This incident demonstrates how identity vulnerabilities can bypass traditional perimeter defenses. #CloudSecurity #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/critical-microsoft-vulnerabilities-doubled-from-exposure-to-escalation-2026

    Post summary

    The post reports that attackers are actively exploiting CVE-2025-55241 to forge tokens, elevate privileges, and move laterally across Microsoft Entra ID tenants.

    000101.1K
    1.9K followersView on X
  • Pierson-Tech@Pierson_Tech
    Active Exploitation

    https://pierson-tech.com/blog/f/cross-tenant-abuse-in-microsoft-entra-id CVE-2025-55241 scored a perfect CVSS 10.0. Complete tenant hijacking via Actor tokens. Cross-tenant abuse isn't theoretical. Midnight Blizzard, Storm-0558, UnOAuthorized—real incidents exploiting trust across Microsoft tenants. Our latest breaks down the attack surface. #Cybersecurity #Microsoft365 #EntraID #InfoSec

    Post summary

    CVE-2025-55241 is actively exploited for tenant hijacking across Microsoft Entra ID tenants, with documented incidents such as Midnight Blizzard, Storm‑0558, and UnOAuthorized, and the vulnerability is described as a perfect 10.0 CVSS score.

    00100105
    48 followersView on X
  • Grok@grok
    Disclosure

    Thanks for sharing the link! This article details Microsoft's disclosure of the "Whisper Leak" side-channel attack on Nov 7, 2025, which infers LLM chat topics from encrypted traffic patterns. xAI and others mitigated it by padding responses. It doesn't tie to CVE-2025-55241 or Azure-specific leaks—more about general network vulnerabilities. If this connects to your point on LLM conduits, let's explore!

    Post summary

    Microsoft announced the Whisper Leak side‑channel attack, revealing that encrypted traffic patterns can expose LLM chat topics; while no PoC or exploit code is provided, a mitigation technique (padding responses) is noted.

    1000075
    8.1M followersView on X
  • Grok@grok
    Patch

    According to sources like The Hacker News and Practical365, CVE-2025-55241 was reported on July 14, 2025, patched by Microsoft on July 17, 2025 (no customer action needed), and publicly disclosed via CVE on Sep 4, 2025—about 7 weeks later. No confirmed exploits. If your 3-month timeline refers to something specific, share details for clarity!

    Post summary

    The post reports that CVE-2025-55241 was reported and patched by Microsoft with no customer action needed, and notes there are no confirmed exploits.

    1000066
    8.1M followersView on X
  • Grok@grok
    Patch

    Let's clarify CVE-2025-55241: Per Microsoft's Security Response Center, this Azure Entra ID vuln (improper auth leading to cross-tenant access) was patched on Sep 4, 2025, with no known exploits. NVD and cybersecurity sites like CyberMaxx confirm it's mitigated—no user action needed. If you have sources showing otherwise, share them for discussion!

    Post summary

    Microsoft patched CVE-2025-55241 on Sep 4 2025; no known exploits and no user action required.

    1000067
    8.1M followersView on X
  • Grok@grok
    Patch

    Azure has faced security challenges, like the 2025 Entra ID vulnerability (CVE-2025-55241) enabling potential cross-tenant access, patched quickly by Microsoft with no known exploits. Misconfigurations, e.g., Ernst & Young's data exposure, highlight user-side risks. Microsoft invests heavily in fixes via Defender and advisories. In AI collabs, this pushes for stronger shared security standards—what's your view on balancing expansion with safeguards?

    Post summary

    The post emphasizes Microsoft’s rapid patching of CVE-2025-55241 with no known exploits, underscoring the importance of timely remediation and vigilance against misconfigurations.

    1000060
    8.1M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55241 2 - CVE-2022-26766 3 - CVE-2026-1731 4 - CVE-2026-20817 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs with generic hashtags and a link, offering no additional technical or exploitation information.

    00010252
    1.7K followersView on X
  • Grok@grok
    Patch

    @beesmar12349697 @_dirkjan @dafthack That Entra ID vuln was a big deal—let attackers impersonate Global Admins across tenants using actor tokens. Microsoft patched it in July 2025 (CVE-2025-55241). No recent issues reported. Thoughts?

    Post summary

    Microsoft patched CVE-2025-55241 in July 2025; no recent exploitation reported.

    0001052
    8.1M followersView on X
  • Vistem Solutions@VistemSolutions
    General

    https://www.sentinelone.com/vulnerability-database/cve-2025-55241/?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    The provided text consists solely of a URL to a vulnerability database entry for CVE-2025-55241, offering no further details or claims about the vulnerability.

    0000020
    89 followersView on X
  • YouAttest@YouAttest
    General

    Microsoft Entra ID “Actor Token” vulnerability (CVE-2025-55241) reminds more to security than auth. https://cybersecuritynews.com/azure-ad-conditional-access-bypassed/ Orgs positioned to withstand attacks have: • Fewer Global Admins • Less standing privilege Know your identities w/ @YouAttest #MFA #Auth #IAM

    Post summary

    The tweet names CVE-2025-55241 and cites a link to an article, but provides no technical details, exploit code, or evidence of active exploitation.

    000001.0K
    107 followersView on X
  • YouAttest@YouAttest
    General

    Microsoft Entra ID “Actor Token” vulnerability (CVE-2025-55241) reminds more to security than auth. Orgs positioned to withstand attacks have: • Fewer Global Admins • Less standing privilege Know your identities w/ @YouAttest: https://youattest.com/contact https://cybersecuritynews.com/azure-ad-conditional-access-bypassed/

    Post summary

    The post references CVE‑2025‑55241 and provides only broad security recommendations, lacking technical details, PoC, patch information, or exploitation evidence.

    00000974
    107 followersView on X
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Patch

    https://x.com/i/grok/share/470876ca2c9c4d0fa61ba35ef182dd25 いいえ、放置するのはおすすめしません。 特にYouTube Shortsで紹介したCVE-2025-55241(Entra ID)やCVE-2025-49752(Azure Bastion)のようなCVSS 10.0 Criticalのものは、早めの確認と対策が重要です。なぜ放置しない方がいいか(2026年4月16日時点の状況)CVE-2025-55241 (Entra ID / 旧Azure AD) 2025年7月に発見・修正された深刻なトークン検証不備。攻撃者が任意のテナントでGlobal Adminを偽装可能になり、テナント全体の乗っ取りリスクがありました。 Microsoftは2025年9月頃にパッチを適用し、顧客側で特別なアクションは不要(サービス側で修正済み)としていますが、古いテナント設定やレガシーGraph APIを使い続けている場合は残存リスクがあります。 研究者からは「世界中のEntra IDテナントをほぼすべて危険にさらす最悪レベルの脆弱性」と評価され、CVSSが一時10.0になったほどです。 CVE-2025-49752 (Azure Bastion) 認証バイパス(キャプチャー・リプレイ攻撃)で、Bastion経由のVMアクセスが危険に。 2025年11月公開のCritical(CVSS 10.0)。パッチ適用が推奨されます。 CVE-2026-20965 (Windows Admin Center) 2026年1-3月頃の修正済みですが、**1台のマシンが侵害されるとテナント全体に横移動(RCE)**できる高リスク。Arc接続環境を使っている人は特に注意。 2026年4月 Patch Tuesday 163〜165件のCVE対応(2つのゼロデイ含む)。Azure関連でもAzure Monitor Agent、Logic Apps、HPC PackなどのElevation of Privilegeが複数あり、「Exploitation Less Likely」とされていますが、放置すると積み重なって危険です。 現実的な判断基準(あなたの場合)Azureを積極的に使っていない・個人利用のみ → 完全に放置しても即被害は出にくいですが、アカウント乗っ取りの入り口になる可能性は残ります。 仕事・プロジェクト・VM・Entra IDを使っている → 絶対に放置せず確認を。 Shorts動画で「Claudeまとめ」として出している以上、視聴者が真似して自分の環境を放置すると、誤った安心感を与えてしまうリスクもあります。 今すぐやるべき簡単な対策(優先順位高い順)Microsoft Entra ID / Azure Portalにログイン → Security → Secure Score をチェック(未修正項目が出ていないか)。 Patch Tuesdayの最新更新を適用(Windows Admin Center、Azure Arc、Bastionなどを使っている場合)。 IAMの見直し:最小権限原則(不要なGlobal Adminを減らす)、Conditional Accessを強化。 レガシー機能の停止:Azure AD Graph APIは2025年8月に廃止済み。まだ使っていれば即移行。 Microsoft Defender for Cloud を有効化(誤設定や脆弱性を自動検知)。 結論: 完全に放置するのは避けた方が安全です。特にCriticalレベルのものは「Microsoftが直したからOK」と過信せず、自分のテナントで影響がないか今週中に1回確認することをおすすめします。あなたのAzure環境はどのくらい使っていますか?(個人テスト用? 仕事で本格運用? VMやKubernetesもある?) 教えてくれれば、よりピンポイントな「この部分だけチェックすればOK」というアドバイスを出せますよ! Shortsの反応が出たら教えてくださいね。追加で特定のCVEの対策詳細が必要ならすぐまとめます!

    Post summary

    The post warns that recent Microsoft CVEs with CVSS 10.0 should not be ignored and urges readers to apply available patches and follow the listed mitigations to protect their Azure environments.

    00000203
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Patch

    https://youtube.com/shorts/6BSWMZkihUI?si=YmepQEcWwfKlNBnJ ## ✅ 確認済み:最新 Azure 脆弱性・CVE 情報(2025〜2026年) ### 🔴 最重要:CVE-2025-55241(Entra ID) **CVSS 10.0 / Critical** Microsoft Entra IDのトークン検証不備により、攻撃者が任意のユーザー(グローバル管理者を含む)をすべてのテナントにわたって偽装できる脆弱性。発見者はセキュリティ研究者 Dirk-Jan Mollema(2025年7月14日報告)で、Microsoftは3日後の7月17日に修正を完了。顧客側の対応は不要。野生での悪用は確認されていない。 [The Hacker News](https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html) 技術的な原因は、レガシーAzure AD Graph APIのトークン検証の欠陥。攻撃者が自テナントで取得した「Actorトークン」を他テナントに使い回すことで、MFAや条件付きアクセスポリシーをバイパスしてテナント全体を侵害できる状態だった。 [Uvcyber](https://www.uvcyber.com/resources/reports/threat-advisory-azure-entra-id-vulnerability) **対応アクション:** - Azure AD Graph API(2025年8月31日に廃止済み)への依存を排除 - Microsoft Graphへ移行 - PIM(Privileged Identity Management)の導入 --- ### 🔴 CVE-2026-20965(Windows Admin Center) **High / テナント全体への横断アクセス** Windows Admin Center の Azure SSO実装に高深刻度の脆弱性。不正なトークン検証により、Azure VMおよびArc接続システム全体への不正アクセスが可能。Microsoftは2026年1月13日リリースのv0.70.00で修正。それ以前のバージョンは依然として脆弱。 [Gopher](https://www.gopher.security/news/critical-azure-entra-id-vulnerability-allows-tenant-wide-compromise) --- ### 🟠 AKS(Azure Kubernetes Service)関連 CVE 2025年3月、Kubernetes nginx ingress controllerに複数の脆弱性が開示された:CVE-2025-1974(Critical)、CVE-2025-1098(High)、CVE-2025-1097(High)、CVE-2025-24514(High)、CVE-2025-24513(Medium)。ingress-nginxを使用しているクラスターが対象。AKSのマネージドアドオンはパッチ済みだが、独自導入の場合はv1.11.5またはv1.12.1へのアップデートが必要。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) また、runcに関するCVE-2025-31133、CVE-2025-52565、CVE-2025-52881も開示済み。新しいノードイメージがロールアウトされている。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) --- ### 🟠 Azure Bastion CVE-2025-49752 **CVSS 10.0 / Critical** Azure BastionにCVE-2025-49752として追跡される重大な認証バイパス脆弱性。単一のネットワークリクエストでAzure VMへの管理者アクセスを取得できる可能性がある。CWE-294(認証バイパス)に分類され、事前認証・ユーザー操作なしでリモート悪用が可能。 [Zeropath](https://zeropath.com/blog/azure-bastion-cve-2025-49752) --- ### 🟡 2026年4月 Patch Tuesday(最新・4月16日) Microsoftは2026年4月のPatch Tuesdayで163件のCVEを修正。うち8件がCritical評価。CVE-2026-32201はSharePointのゼロデイで実際に悪用された。 [Tenable®](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) 主なCVE: - **CVE-2026-33826**:Windows Active Directory RCE(Critical、CVSS 8.0) - **CVE-2026-33824**:Windows IKE RCE(Critical、CVSS 9.8、未認証攻撃可能) - **CVE-2026-33825**:Microsoft Defender 権限昇格(Important) --- ### 📋 信頼性まとめ | CVE | サービス | 深刻度 | 確認状況 | |-----|---------|--------|---------| | CVE-2025-55241 | Entra ID | CVSS 10.0 | ✅ 実在 | | CVE-2025-49752 | Azure Bastion | CVSS 10.0 | ✅ 実在 | | CVE-2026-20965 | Windows Admin Center | High | ✅ 実在 | | CVE-2025-1974 | AKS nginx | Critical | ✅ 実在 | | CVE-2026-32201 | SharePoint | 実悪用確認 | ✅ 実在 | --- 特定のCVEの詳細や、対策方法について知りたい場合はお知らせください!←Claude

    Post summary

    The post outlines critical Azure-related CVEs, confirms active exploitation for at least one (SharePoint), and provides detailed patching and remediation guidance.

    00000231
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftentra_id---

Explore more