Microsoft Entra ID에서 원격 코드 실행 취약점이 발견되었습니다.
Microsoft는 Entra ID에서 CVSS 10.0의 최대 심각도 보안 취약점이 발견되었으며, 이미 악용 사례가 발생했다고 경고했습니다. 이 취약점은 클라우드 기반의 아이덴티티 및 액세스 관리 서비스에 영향을 미치며, 구버전의 Azure Active Directory에서 발생합니다. 고객은 특별한 조치를 취할 필요가 없다고 밝혔습니다.
A critical remote code execution vulnerability in Microsoft Entra ID has been exploited in the wild.
Microsoft has warned about a maximum-severity security vulnerability in Entra ID, with a CVSS score of 10.0, that has been exploited in the wild. This remote code execution flaw affects the company's cloud-based identity and access management service, formerly known as Azure Active Directory. Fortunately, Microsoft noted that no customer action is required.