Microsoft has patched a severe vulnerability in its Entra ID service (formerly Azure Active Directory) that would have allowed attackers to impersonate any user — including Global Administrators — across any tenant. Tracked as CVE-2025-55241, the bug stemmed from flawed token validation in legacy APIs. While Microsoft says there is no evidence of in-the-wild exploitation, the implications of the issue were far reaching — and the fix, rolled out on July 17, 2025, relieved many organizations of a potentially devastating risk.

The Vulnerability: What Went Wrong

  • The issue was discovered and reported by researcher Dirk-jan Mollema on July 14, 2025. The flaw could have enabled compromise of every Entra ID tenant globally, except in certain national cloud instances.
  • The root cause was a combination of service-to-service (S2S) actor tokens issued by Microsoft’s Access Control Service (ACS) and a legacy Azure AD Graph API (graph.windows.net) that did not properly verify which tenant had issued a token. In effect, an attacker could use a token from their own, non-privileged environment to impersonate a Global Admin in any target tenant.
  • Because these tokens were subject to Microsoft’s Conditional Access policies, the attacker could bypass protections like multi-factor authentication (MFA). In addition, the legacy Graph API lacked sufficient logging, meaning an attacker’s actions might have left no trace.

Background Context
Microsoft has been in the process of deprecating the Azure AD Graph API, having officially retired it as of August 31, 2025, and urging all customers to migrate to Microsoft Graph. The vulnerability exploited precisely this legacy API, highlighting risks that can persist even after product or API deprecation announcements.

This discovery follows a pattern of recent cloud-security risks: misconfigurations, legacy component weaknesses, and insufficient token or permission validation have all featured in breaches and vulnerability disclosures. Organizations are increasingly targeted via such attack vectors, which often bypass standard defenses once inside privileged access boundaries.

Expert Insights
According to Mitiga, a cloud security firm, successful exploitation of CVE-2025-55241 would let attackers bypass not only MFA but also Conditional Access and logging, “leaving no trail of the incident.” Roei Sherman of Mitiga further explained that the weakness allowed actor tokens — which should have a trusted, validated origin — to be misused because of the legacy API’s failure to validate the issuing tenant.

Mollema emphasized that impersonation by an attacker holding Global Admin privileges inside another tenant could lead to full tenant compromise: creating accounts, elevating permissions, accessing sensitive data, including everything from SharePoint Online to device-related and BitLocker key info.

What Has Microsoft Done, and What Users Should Know

  • The patch was released on July 17, 2025; Microsoft indicates that no further customer action is required.
  • Microsoft classifies this form of cross-tenant access as a “High-privileged access” (HPA) issue, as it allows an application or service to obtain broad access to customer content without sufficient proof of user context.
  • With the legacy Azure AD Graph API fully retired as of late August 2025, Microsoft had already urged any remaining users to migrate applications to Microsoft Graph.

For IT security teams, the incident underlines the importance of: ensuring no systems depend on deprecated APIs, auditing use of actor tokens or service-to-service credentials, verifying that Conditional Access and MFA policies cover all control points, and ensuring robust logging is enabled for all identity and access management (IAM) functions.

The discovery and patching of CVE-2025-55241 demonstrate both how legacy components and lapses in validation can open massive security holes — and how vigilant research and responsive action are essential to cloud security. While Microsoft’s swift mitigation is commendable, organizations should view this as a warning shot: even deprecated APIs can harbour critical risks, and cross-tenant identity models demand rigorous validation and monitoring. Ensuring best practices in identity and access management has never been more important.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *