CVE-2017-8613: Microsoft Azure Active Directory Connect

High severity, CVSS 8.1. EPSS: 3.7% chance of exploitation in the next 30 days.

Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."

Affected products

  • Microsoft Azure Active Directory Connect: up to and including 1.1.524.0

Published 2017-06-29. Last modified 2026-06-17.