First published: Thu Aug 22 2024(Updated: )
<p>Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Entra | ||
Microsoft Entra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43477 is rated as a high severity vulnerability due to its potential to allow unauthorized access and control over Verifiable IDs.
To fix CVE-2024-43477, ensure that appropriate access controls are implemented in the Decentralized Identity Services configuration.
CVE-2024-43477 affects users of Microsoft Entra ID who utilize Decentralized Identity Services.
CVE-2024-43477 enables an unauthenticated attacker to disable Verifiable IDs on another tenant.
As of now, there is no confirmation that CVE-2024-43477 is actively being exploited in the wild.