👩💻 I SPy: Escalating to Entra ID's Global Admin with a first-party app
Backdooring Microsoft's applications is far from over. A vulnerable, built-in SP that could have allowed escalation from Application Administrator to any hybrid tenant user, including Global Admin, was discovered.
https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/
#azure
Post #1209
438

- ❤ 1
- 👍 1
- 🔥 1