Microsoft’s SSPR portal may expose sensitive account details to unauthenticated users, including whether an Entra ID account exists and its registered password-reset methods. Such exposure might assist attackers in refining their phishing, password-spraying, and social engineering attacks on corporate networks. Microsoft Entra ID’s Self-Service Password Reset (SSPR) feature lets users reset forgotten passwords through the public portal by entering their email and choosing a registered verification method. Research by Matthew Coady highlights a problematic aspect of the portal: the server responses vary based on the provided account. This variability can indicate the existence of an account, eligibility for SSPR, and which...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!