Loading HuntDB...

CVE-2025-55241

CRITICAL
Published 2025-09-04T23:09:53.490Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-55241. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
10.0
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
Not Available
Attack Complexity
Not Available
Privileges Required
Not Available
User Interaction
Not Available
Scope
Not Available

Impact Metrics

Confidentiality
Not Available
Integrity
Not Available
Availability
Not Available

Description

No description available

Available Exploits

No exploits available for this CVE.

Related News

Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants

A critical token validation failure in Microsoft Entra ID (previously Azure Active Directory) could have allowed attackers to impersonate any user, including Global Administrators, across any tenant. The vulnerability, tracked as CVE-2025-55241, has been assi…

Internet 2025-09-22 05:47

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Malicious code in bioql (PyPI)

Affected Products (ENISA)

microsoft
microsoft entra

ENISA Scoring

CVSS Score (3.1)

10.0
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C

EPSS Score

0.090
probability

Data provided by ENISA EU Vulnerability Database. Last updated: October 3, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed CRITICAL

GHSA-jpqg-vx8m-6w9j

Advisory Details

Azure Entra Elevation of Privilege Vulnerability

CVSS Scoring

CVSS Score

9.0

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: September 5, 2025, Modified: September 18, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

11 posts
Reddit 1 month, 2 weeks ago
Steve_Dobbs_69
Exploit

CVE-2025-55241: Azure Entra Elevation of Privilege Vulnerability - Cybersecurity Exploit Tracker by Ameeba

1
1.0
View Original High Risk
Reddit 1 month, 2 weeks ago
crstux
Exploit

🔥 Top 10 Trending CVEs (24/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-26399](https://nvd.nist.gov/vuln/detail/CVE-2025-26399)** - 📝 SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands …

2
2.0
View Original High Risk
Reddit 1 month, 2 weeks ago
Suspicious_Bug4112

Microsoft Entra ID Flaw Allows Global Admin Impersonation **Date:** 22-Sep-25 A critical vulnerability, tracked as CVE-2025-55241, has been identified within Microsoft Entra ID, previously known as Azure Active Directory, allowing attackers to potentially assume global administrative control across all Microsoft tenants using a single compromised Actor token. Discovered by security …

Reddit 1 month, 2 weeks ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (22/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-57822](https://nvd.nist.gov/vuln/detail/CVE-2025-57822)** - 📝 Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could …

1
1.0
View Original High Risk
Reddit 1 month, 2 weeks ago
falconupkid

Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants A critical token validation failure in Microsoft Entra ID (previously Azure Active Directory) could have allowed attackers to impersonate any user, including Global Administrators, across any tenant. The vulnerability, tracked as... **CVEs:** CVE-2025-55241 **Source:** https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html

Reddit 1 month, 2 weeks ago
_cybersecurity_

Microsoft Entra ID Flaw Exposes Companies to Tenant Hijacking **A security vulnerability in Microsoft Entra ID could have allowed unauthorized access to the identity management system of any organization globally.** **Key Points:** - A combination of legacy actor tokens and an Azure AD Graph API vulnerability enabled tenant access. - …

Reddit 1 month, 3 weeks ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (21/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-24054](https://nvd.nist.gov/vuln/detail/CVE-2025-24054)** - 📝 NTLM Hash Disclosure Spoofing Vulnerability - 📅 **Published:** 11/03/2025 - 📈 **CVSS:** 6.5 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C - 📣 **Mentions:** 85 - ⚠️ **Priority:** {"error":"Priority not found for …

1
1.0
View Original High Risk
Reddit 1 month, 3 weeks ago
Sarunas

Kritinis „Azure Entra ID“ pažeidžiamumas https://preview.redd.it/0e8rwcih3cqf1.png?width=1024&format=png&auto=webp&s=4f474226e07ff2d507a14c4a40add349253843f1 Kritinė „Microsoft“ autentifikacijos spraga, žinoma kaip CVE-2025-55241, galėjo leisti kibernetiniams nusikaltėliams kompromituoti praktiškai kiekvieną pasaulyje esantį Entra ID nuomininką. Pažeidžiamumas, vasarą pašalintas ir šį mėnesį viešai atskleistas, gavo aukščiausią – 10,0 – CVSS įvertinimą, nors kol kas nėra įrodymų, kad jis būtų buvęs išnaudotas …

Reddit 1 month, 3 weeks ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (20/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-55241](https://nvd.nist.gov/vuln/detail/CVE-2025-55241)** - 📝 Azure Entra Elevation of Privilege Vulnerability - 📅 **Published:** 04/09/2025 - 📈 **CVSS:** 10 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C - 📣 **Mentions:** 19 - ⚠️ **Priority:** 2 - 📝 …

1
1.0
View Original High Risk
Reddit 1 month, 3 weeks ago
n0wh3r3h3r3

Microsoft Entra ID aka Azure Active Directory kapott! Microsoft Entra ID ist der cloudbasierte Identitäts- und Zugriffsverwaltungsdienst von Microsoft, früher bekannt als **Azure Active Directory**. Okay, ab hier braucht man eigentlich nicht mehr weiterlesen... Active Directory... in the Cloud... das kommt sicher suuuper!!1111 Hätte uns doch bloss jemand gewarnt. Unternehmen …

References

Published: 2025-09-04T23:09:53.490Z
Last Modified: 2025-09-18T21:42:48.094Z
Copied to clipboard!