SMTP Matching Abuse in Azure AD
semperis.com | blog | #cloud | #active-directory | #privilege-escalation | #research | #azure-ad | #hybrid-identity | #smtp-matching
Summary
Semperis research: anyone who can create AD accounts can abuse SMTP matching to reset Azure AD user passwords and, with prerequisites, gain privileged access via eligible role assignments.
- Published
- Collected
Skip to content