Executive brief
Microsoft Azure Active Directory, a cloud-based identity and access management service, is vulnerable to a flaw that could allow an attacker to disrupt the service. By sending specific network requests, an unauthorized user can trigger an infinite loop that consumes system resources, leading to a denial of service. This could prevent legitimate users from logging into their accounts or accessing corporate applications.
Technical details
A denial of service vulnerability exists in Microsoft Azure Active Directory due to an infinite loop (CWE-835) caused by a loop with an unreachable exit condition. An unauthenticated attacker can exploit this over the network by sending specially crafted requests to the service, leading to uncontrolled resource consumption (CWE-400). The vulnerability affects Azure Active Directory 2021 versions prior to 8.19.2. Successful exploitation results in a complete loss of availability for the affected service component. Microsoft has addressed this issue in version 8.19.2.
Affected products
- Microsoft Azure Active Directory 2021 < 8.19.2
Timeline
- 2026-07-14: advisory: Microsoft published the security advisory.
- 2026-07-14: patched: Fix available in version 8.19.2.