A new vulnerability has been discovered in the Microsoft.Identity.Web NuGet package under specific conditions, potentially exposing sensitive information such as client secrets and certificate details in service logs.
The flaw, identified as CVE-2025-32016, has been rated as moderate, prompting developers to urgently address the issue to prevent unintended data exposure.
The vulnerability impacts confidential client applications such as daemons, web applications, and web APIs.
Sensitive data, including client secrets, Base64-encoded certificates, or certificate paths with password descriptors, could be exposed when service logs are generated under certain conditions.
Affected Scenarios:
Service logs are typically intended for secure handling, but this flaw introduces a risk of data leakage under specific configurations.
Applications using invalid or expired certificates may still be affected, regardless of their log level, though credentials in these cases are not usable due to invalidity.
Impact
The vulnerability primarily impacts services meeting the following conditions:
Other credential descriptions unaffected include those not tied to client secrets, Base64-encoded certificates, or credential paths. Applications whose logs are managed securely are also not impacted.
Microsoft has released fixes for the vulnerability. Developers are advised to upgrade to:
For applications unable to upgrade immediately, the following measures are suggested:
This discovery underscores the importance of secure logging practices and timely application updates.
Developers are strongly encouraged to upgrade to the patched versions or implement alternative workarounds to safeguard sensitive information.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
The Sekoia TDR (Threat Detection & Research) team has reported on a sophisticated network infrastructure…
The Socket Threat Research Team has unearthed a trio of malicious packages, two hosted on…
Hackers are now exploiting a legitimate Microsoft utility, mavinject.exe, to inject malicious DLLs into unsuspecting…
Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network edge…
Joining Criminal IP at Booth S-634 | South Expo, Moscone Center | April 28 –…
Cybersecurity researchers have uncovered critical SQL injection vulnerabilities in four TP-Link router models, enabling attackers…