CVE-2025-54882 affects Himmelblau, an interoperability suite for Microsoft Azure Entra ID and Intune, specifically versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0. The vulnerability involves the storage of cloud TGTs in the Kerberos credential cache with world-readable permissions, allowing unauthorized access to sensitive credentials. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating a local attack vector with low complexity, requiring local user privileges. A successful exploit could lead to high confidentiality and integrity impacts, as attackers could steal credentials and potentially impersonate users. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. Patches are available in Himmelblau versions 0.9.22 and 1.2.0, and a workaround involves restricting read access to Himmelblau caches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.8.0, < 0.9.22CPE matchmatch criteria | cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.2.0CPE matchmatch criteria | cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.