VDB
GCVE-110-CLOUD-2024-0040
GCVE-110-CLOUD-2024-0040
Advisory Published
A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Azure | Microsoft Entra ID, Microsoft Dynamics 365 Supply Chain Visibility | — | — |
| Azure | Cloud Services | — | — |
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.