MENA-relevant: this CVE surfaced in at least one tracked MENA case, not just present in the undifferentiated CISA catalog.
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.