The vulnerability resides in Entra ID, formerly known as Azure Active Directory, which serves as the cornerstone of identity and access management for Microsoft’s cloud customers. According to Microsoft’s advisory, the flaw involves “deserialization of untrusted data,” where software reconstructs data from an untrusted source without adequate validation. This allows an unauthorized attacker to execute code remotely, with low attack complexity and no need for user interaction or privileges.
Microsoft credited principal security engineer Robert Fitzpatrick with discovering and reporting the vulnerability. However, the company has not disclosed when the exploitation began, who is behind the attacks, how widespread they are, or what actions attackers took after successful exploitation. No public technical details of the attack chain have been provided.
Administrators can breathe a sigh of relief that no manual patching is required. Because Entra ID is a Microsoft-operated cloud service, Redmond was able to fix the vulnerable infrastructure directly rather than shipping an update for customers to install. The CVSS metrics — a perfect 10 — highlight the severe risk: remotely exploitable, low attack complexity, no required privileges or user interaction, and potentially high impact on confidentiality, integrity, and availability.
Despite the patching, the lack of transparency has raised concerns among security professionals. Customers are left wondering whether attackers were able to access authentication tokens, user credentials, or other sensitive data during the window of exploitation. Microsoft has not yet responded to questions from The Register about the incident’s scope.
The episode underscores the unique challenges of cloud service security: while providers can rapidly patch backend infrastructure, the opacity of incident details can leave customers uncertain about their own exposure. As organizations increasingly rely on Entra ID for single sign-on and conditional access, any compromise of the identity fabric carries far-reaching implications.