Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

SMTP Matching Abuse in Azure AD

Summary

Semperis research: anyone who can create AD accounts can abuse SMTP matching to reset Azure AD user passwords and, with prerequisites, gain privileged access via eligible role assignments.
Published
Collected

original ↗