Knowledge of a valid public and private exponent gives , a nonzero multiple of . Writing it as with odd and testing random bases produces a nontrivial square root of one modulo with high probability; a greatest common divisor then factors . Thus one customer's private key under a shared semiprime modulus compromises every exponent using that modulus.
Codex Wiki