Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft reportedly fixed CVE-2025-55241 in its Entra ID service by July 17, 2025, with no customer action required. Security researcher Dirk-jan Mollema said the flaw could have let a token requested in one tenant impersonate users—including Global Administrators—in another. That describes a demonstrated capability in his lab, not evidence that customer tenants were compromised.

What was CVE-2025-55241?

CVE-2025-55241 was a service-side vulnerability involving Microsoft Entra ID, the identity service formerly known as Azure Active Directory. Mollema’s account describes two issues working together: undocumented “Actor tokens” used for communication between Microsoft backend services, and insufficient validation of the originating tenant in the legacy Azure AD Graph API. The API did not adequately establish that a token requesting access belonged to the tenant whose identities it could reach. Mollema’s technical write-up

In his lab, Mollema said he could use a token requested in his own tenant to authenticate as users in other tenants, including Global Administrators. He summarized the demonstrated capability as: “Effectively this means that with a token I requested in my lab tenant I could authenticate as any user, including Global Admins, in any other tenant.” This is his description of the lab demonstration; it does not establish that an attacker used the flaw against customer tenants.

What could cross-tenant impersonation have exposed?

Mollema described potential access to Entra ID user details, groups and roles, tenant settings, Conditional Access policies, applications and service principals, application permissions, device data, and synchronized BitLocker keys. If an attacker could impersonate a Global Administrator, the resulting identity could potentially make broad tenant changes and access services that rely on Entra ID authentication, including Microsoft 365 and Azure resources. These are capabilities associated with the reported flaw, not a list of confirmed compromises.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Could Conditional Access or tenant logs have caught it?

Mollema said the Actor tokens were not subject to Conditional Access and that requesting them generated no logs in the victim tenant. He also described Azure AD Graph as having very limited API-level logging. These points matter because normal tenant-side controls or records might not have provided the visibility administrators expect. The available reporting does not establish that Conditional Access or tenant logs would have detected this path.

When was it fixed, and do customers need to act?

According to The Hacker News report published September 22, 2025, Mollema reported the issue to Microsoft on July 14, 2025, Microsoft had addressed it by July 17, and the CVE was issued on September 4. The report says the fix was applied on Microsoft’s side and no customer action was required. Because the issue was in a cloud service, this was not a customer-installed software patch. The Microsoft advisory endpoint was not readable in the available record, so the dates and no-action statement here are attributed to that independent report.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How severe was the vulnerability?

Published severity figures differ, so neither should be presented as a definitive current official score without checking the live Microsoft or NVD record:

  • GitHub Advisory Database marks the issue critical and displays CVSS v3 9.0. The entry is labeled unreviewed and lists affected and patched versions as unknown.
  • The Hacker News reports a CVSS score of 10.0.

The Hacker News report said there was no indication of exploitation in the wild at the time it was published on September 22, 2025. Mollema’s account does not provide a victim count or prevalence figure. Neither point should be read as proof that exploitation never occurred.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.