National Cyber Warfare Foundation (NCWF) Forums


Experts Uncover How Cybercriminals Could Exploit Microsoft Entra ID for Elevated Privilege


0 user ratings
2023-08-28 16:36:15
milo
Blue Team (CND)

 - archive -- 
Cybersecurity researchers have discovered a case of privilege escalation associated with a Microsoft Entra ID (formerly Azure Active Directory) application by taking advantage of an abandoned reply URL.
"An attacker could leverage this abandoned URL to redirect authorization codes to themselves, exchanging the ill-gotten authorization codes for access tokens," Secureworks Counter Threat Unit (



Source: TheHackerNews
Source Link: https://thehackernews.com/2023/08/experts-uncover-how-cybercriminals.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.