Microsoft END’s vulnerability allows full account control – and does not take any effort


  • 10% of the 150,000 SaaS applications proposed could be affected by the vulnerability of identification entered
  • He was disclosed for the first time in 2023, but many applications remain affected
  • Application suppliers must issue fixes or you may take account repurchase

Semperis has published new research by discovering a severe flaw in Microsoft Entrole Identification, called Noauth, and its effects could extend over 10% of SaaS applications worldwide.

Vulnerability implies a cross -authentication defect affecting the ENTE identification integrations – the attackers could execute the full repurchase of the account with a single access to a ENV tenant and the victim’s e -mail.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top