Potential Risk of Privilege Escalation in Azure AD Applications

Microsoft Security Header
Summary Summary Microsoft has developed mitigations for an insecure anti-pattern used in Azure AD (AAD) applications highlighted by Descope, and reported to Microsoft, where use of the email claim from access tokens for authorization can lead to an escalation of privilege. An attacker can falsify the email claim in tokens issued to applications.

Source – Microsoft Security Response Center

All content and images belong to their respected owners, this article is curated for informational purposes only.

Total
0
Shares
Previous Post
Microsoft Security Header

Microsoft Response to Layer 7 Distributed Denial of Service (DDoS) Attacks

Next Post
Microsoft Security Header

Congratulations to the Top MSRC 2023 Q2 Security Researchers!

Related Posts