Microsoft Entra OAuth Flaw Exposed Internal Apps to Unauthorized Access
by anonkiller - Sunday August 10, 2025 at 03:12 PM
#1
Researchers at Eye Security uncovered vulnerabilities in Microsoft’s Entra OAuth system that could allow attackers to gain unauthorized access to internal applications. The issue stemmed from misconfigurations in the OAuth consent process, where malicious applications could mimic legitimate ones and trick users into granting excessive permissions. This could lead to data theft, manipulation of AI models like Copilot, or access to sensitive internal tools. The flaw was reported to Microsoft in April 2025, patched by July 2025, and classified as moderate severity, but it highlights broader risks in cloud-based authentication systems, especially in hybrid environments. Eye Security noted parallels to earlier large-scale SharePoint vulnerabilities they discovered in July 2025, reinforcing that such misconfigurations are not isolated. The risks include business email compromise, lateral movement within networks, and targeted phishing. 


To mitigate these threats, organizations should immediately audit OAuth consents, enforce least-privilege access, use Entra ID governance tools to review and revoke suspicious permissions, and integrate automated scanning to detect anomalies. This incident underscores the balance between usability and security in OAuth and the need for stronger collaboration between vendors and researchers to prevent future exploits.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google confirms data breach exposed potential Google Ads customers' info lulagain 0 69 Yesterday, 08:58 PM
Last Post: lulagain
  ‘A million calls an hour’: Israel relying on Microsoft cloud for expansive surveillan lulagain 1 119 Yesterday, 04:20 PM
Last Post: 0btkop
  6.4 million Bouygues Telecom just had their data exposed in a huge data breach – and lulagain 1 116 Yesterday, 09:45 AM
Last Post: KingDice
  LG Innotek Camera Flaws Could Give Hackers Full Admin Access dkahffkd 0 115 08-08-2025, 02:36 PM
Last Post: dkahffkd
  Akira ransomware abuses CPU tuning tool to disable Microsoft Defender lulagain 0 114 08-07-2025, 10:17 PM
Last Post: lulagain

Forum Jump:


 Users browsing this thread: 1 Guest(s)