CRITICAL

CVE-2024-49035

Microsoft Partner Center 2024-11-26 CVSS v3.1
CVSS
9.8
KEV

Description

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Summary dbcve.org

This is an improper access control vulnerability in Microsoft's partner portal (Partner.Microsoft.com) that allows an unauthenticated attacker to gain elevated privileges over the network. The vulnerability stems from a failure to properly enforce authentication and authorization checks on certain endpoints or functionality, enabling remote privilege escalation without any valid credentials.

Mitigation

Apply Microsoft's security update for this vulnerability once released; until then, monitor for suspicious unauthorized access attempts to Partner.Microsoft.com and restrict network exposure where possible.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

1.3%
Probability of exploitation in next 30 days
68.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE