Back to directory
WRITEUP #106

UnOAuthorized: Privilege Elevation Through Microsoft Applications

CloudPrivilege escalation
by@ericonidentity(Eric Woodruff)
Program
Microsoft (Entra ID / Azure AD)
Published
Aug 7, 2024
Added to HackDex
Aug 14, 2024
Read Full Writeuphttps://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
Escalating Privileges in Google Cloud via Open Groups
CloudPrivilege escalation
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
CloudPrivilege escalation
Exploiting Broken Authentication Control In GraphQL
CloudGraphQL

Built with ❤️ by Shubham Rawat