Security
Headlines
HeadlinesLatestCVEs

Headline

Potential Risk of Privilege Escalation in Azure AD Applications

Summary Summary Microsoft has developed mitigations for an insecure anti-pattern used in Azure AD (AAD) applications highlighted by Descope, and reported to Microsoft, where use of the email claim from access tokens for authorization can lead to an escalation of privilege. An attacker can falsify the email claim in tokens issued to applications.

msrc-blog
#microsoft#auth

msrc-blog: Latest News

What’s new in the MSRC Report Abuse Portal and API