Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants
Attackers would have been able to assume the identity of any user, including Global Administrators, across any tenant due to a significant token validation error in Microsoft Entra ID (formerly Azure Active Directory).
The maximum CVSS score of 10.0 has been assigned to the vulnerability, which is recorded as CVE-2025-55241. Microsoft has referred to it as an Azure Entra privilege escalation vulnerability. No evidence suggests that the problem was used in the wild. As of July 17, 2025, the Windows manufacturer has fixed it, thus no client action is necessary.
According to security researcher Dirk-jan Mollema, who found and disclosed the vulnerability on July 14, it allowed for the compromise of all Entra ID tenants worldwide, most likely with the exception of national cloud deployme...

