Elevation of Privilege Vulnerability in Microsoft Azure Entra
CVE-2025-55241

9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
4 September 2025

What is CVE-2025-55241?

The Azure Entra elevation of privilege vulnerability allows an attacker to exploit the system by gaining unauthorized access to sensitive operations or data within Azure Entra. This can lead to significant security risks, including the potential exposure of confidential information and unauthorized modifications in cloud environments. Users are strongly advised to update their systems to the latest versions to mitigate this risk.

Affected Version(s)

Microsoft Entra Unknown

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55241 : Elevation of Privilege Vulnerability in Microsoft Azure Entra