Skip to main content
Vulnerability Disclosure

Security Vectors

Vulnerabilities identified by the Modern 42 Labs security research team. We specialise in enterprise IAM and PAM systems, uncovering vulnerabilities within the tools we implement daily.

VULN-172966

Moderate

CVSS Score: N/A

Fixed

Intune MAM App Protection Conditional Access Bypass

Vendor: Microsoft·Product: Intune MAM / Entra ID Conditional Access

A self-attested Intune MAM enrolment satisfies the 'require app protection policy' Conditional Access grant, letting the holder of a user's refresh token reach app-protected data without a genuine managed device or app.

Impact

Post-authentication access to the Office 365 mail, files and chat an app protection policy was meant to gate.

Read More

CVE-2025-XXXXX

Important

CVSS Score: ???

Disclosed

Microsoft Entra ID Multi-Factor Authentication Bypass

Vendor: Microsoft·Product: Entra ID Conditional Access

A authentication bypass vulnerability in Microsoft Entra ID that allows attackers to bypass multi-factor authentication mechanisms under specific conditions.

Impact

MFA bypass to allow access to unauthorized access to protected resources

Read More

Want us to have a look at something?

If you believe you've discovered a security vulnerability in one of our systems or want to collaborate on security research, please reach out to us.

Contact Us

We use cookies

We use cookies and similar technologies to help personalise content, measure the performance of our site, and provide a better experience. By clicking Accept, you consent to the use of all cookies.
Learn more.