Summary
Microsoft patched a critical CVSS 10.0 remote code execution vulnerability in Entra ID that was exploited in the wild. The flaw allowed unauthenticated attackers to run arbitrary code by sending malicious data to the identity service.
Take Action:
Microsoft already fixed this specific cloud flaw so you do not need to take action. You should still check your identity logs for any strange activity that happened before the patch was applied and track this advisory for vendor evaluation.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)