Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99294 | third party advisory vdb entry |
https://technet.microsoft.com/library/security/4033453 | mitigation vendor advisory |