CyberRota Analysis
AI-GeneratedA vulnerability exists in Microsoft’s SSSD when integrated with Microsoft Entra ID, where unsanitized search inputs can lead to unauthorized information disclosure through manipulated directory query filters. Local users can exploit this flaw by crafting specific lookup requests, potentially exposing sensitive data. Organizations using SSSD with Microsoft Entra ID should prioritize patching to mitigate the risk of data leakage.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory.
Related CVEs
Other vulnerabilities affecting the same vendor(s)