This Microsoft Entrance serious parade could have let the hackers infiltrate any user, so the patch now


  • The actor tokens authorized an identity theft between the tenants without journalization or security checks
  • CVE-2025-55241 Activates the overall access administration via API Azure AD GRAP
  • Microsoft corrected the flaw in September 2025; Actor tokens and graphic APIs are in progress

Security researchers have found a critical vulnerability in Microsoft END’s ID which could have allowed threat actors to obtain access to the global administrator to practically the tenant of anyone – without being detected in any way.

Vulnerability consists of two things-an inherited service called “actor tokens”, and a critical elevation of the privilege bug followed as CVE-2025-55241.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top