Executive brief
A security vulnerability in Microsoft Azure Active Directory could allow an attacker to disrupt the service remotely. Azure Active Directory is a critical identity management service used by organizations to manage user logins and access to applications. An exploit could result in a denial-of-service, preventing legitimate users from accessing corporate resources and interrupting business operations.
Technical details
A deserialization vulnerability (CWE-502) exists in Microsoft Azure Active Directory. The flaw stems from the service improperly processing untrusted data, which can be exploited by an unauthenticated attacker over the network. By sending a specially crafted request, an attacker can trigger a denial-of-service (DoS) condition, impacting the availability of the identity service. The vulnerability is addressed in version 5.7.1 of the affected component.
Affected products
- Microsoft Azure Active Directory 2021 versions prior to 5.7.1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory