This serious Microsoft fault enters could have allowed computer pirates to infiltrate any user, so patch now




  • The actors tokens allowed the supplant of a cross tenant without registration or security checks
  • CVE-2025-55241 Access to Global Administrator enabled through the deactivated Azure Ad Graph Api
  • Microsoft patched the defect in September 2025; The actors tokens and the GRAPh API are being eliminated.

Security researchers have found a critical vulnerability in Microsoft, ID enters that it could have allowed threat actors to obtain access to global administrator to the tenant practically from any person, without being detected in any way.

Vulnerability consists of two things: an inherited service called “actor tokens”, and a critical elevation of traced privileges errors such as CVE-2025-55241.

Leave a Comment

Your email address will not be published. Required fields are marked *