1 min Security

Microsoft patches critical vulnerability in Entra ID following active exploitation

Microsoft patches critical vulnerability in Entra ID following active exploitation

The vulnerability in Entra ID allowed attackers without privileges to remotely execute code. Users do not need to take any action themselves, the fix has already been implemented.

Through this vulnerability, an attacker could execute code over the network without authentication and with little effort. Robert Fitzpatrick, a principal security engineer at Microsoft, discovered the vulnerability.

Entra ID handles authentication, policy enforcement, and access management for customers of Microsoft 365, Azure, and Dynamics CRM Online, so a vulnerability in that layer has the potential to impact an organization’s entire identity chain.

No action required for users

Microsoft reports that no exploit code is publicly available yet. In Thursday’s advisory, the company writes: “This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.”

That wording is no coincidence. In 2024, Microsoft announced that it would also issue CVEs for critical cloud vulnerabilities it has already resolved. Customers will not need to apply any patches, but they will gain insight into what happened.

Tip: Microsoft is tightening password resets in Entra ID