CVE-2025-5524104.09.2025, 23:15Azure Entra ID Elevation of Privilege VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST10 CRITICALNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HmicrosoftCNA10 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:CCISA-ADPADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 26%VendorProductVersionmicrosoftentra_id-𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55241https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/