CRITICAL
CVE-2024-49035
CVSS
9.8
KEV
Description
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
Summary dbcve.org
This is an improper access control vulnerability in Microsoft's partner portal (Partner.Microsoft.com) that allows an unauthenticated attacker to gain elevated privileges over the network. The vulnerability stems from a failure to properly enforce authentication and authorization checks on certain endpoints or functionality, enabling remote privilege escalation without any valid credentials.
Mitigation
Apply Microsoft's security update for this vulnerability once released; until then, monitor for suspicious unauthorized access attempts to Partner.Microsoft.com and restrict network exposure where possible.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
1.3%
Probability of exploitation in next 30 days
68.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.