A New App Consent Attack: Hidden Consent Grant
semperis.com | blog | #cloud | #vulnerability-research | #privilege-escalation | #entra-id | #permissions | #azure-ad | #consent-phishing
Summary
Semperis found Entra ID's Directory.ReadWrite.All permission can be abused to escalate privileges, disrupt services, or take over a tenant—the Hidden Consent Grant attack, rated potentially severe.
- Published
- Collected
Skip to content