CVE-2024-43477: Microsoft Entra ID Elevation of Privilege Vulnerability
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.
Other sources
Microsoft Entra ID Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43477?
CVE-2024-43477 is rated as a high severity vulnerability due to its potential to allow unauthorized access and control over Verifiable IDs.
How do I fix CVE-2024-43477?
To fix CVE-2024-43477, ensure that appropriate access controls are implemented in the Decentralized Identity Services configuration.
Who is affected by CVE-2024-43477?
CVE-2024-43477 affects users of Microsoft Entra ID who utilize Decentralized Identity Services.
What type of attack does CVE-2024-43477 enable?
CVE-2024-43477 enables an unauthenticated attacker to disable Verifiable IDs on another tenant.
Is CVE-2024-43477 being actively exploited?
As of now, there is no confirmation that CVE-2024-43477 is actively being exploited in the wild.