ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

mediumAdvisoryimportance 30
AI summary · glm-5.3-flash

Zero Day Initiative disclosed an unauthenticated information disclosure vulnerability (CVSS 5.8) in Microsoft Azure Entra ID's OAuth device code grant flow.

ZDI published advisory ZDI-26-629 describing an information disclosure vulnerability in Microsoft Azure Entra ID related to the OAuth device code grant. Remote attackers can disclose sensitive information without authentication. ZDI assigned a CVSS 3.1 score of 5.8; no CVE identifier is listed in the advisory text.

  • Affects OAuth device code grant in Azure Entra ID
  • No authentication required for exploitation
  • ZDI rated the issue CVSS 5.8
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.

This source does not provide full text. Read it at zerodayinitiative.com.