Junglewise Threat Intelligence

CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability

CVE-2024-49035 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-02-25

Vendors: Microsoft.

Executive brief

Microsoft Partner Center (Partner.Microsoft.com) contains an improper access control vulnerability that allows an unauthenticated attacker to elevate privileges over a network. The flaw is tracked as CVE-2024-49035 and has been observed being exploited in the wild.

Affected products

  • Microsoft Partner Center Partner.Microsoft.com

Timeline

  • 2024-11-26: disclosed: NVD Published Date and initial receipt from Microsoft
  • 2025-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-25: exploited: Reported as exploited in the wild in advisory metadata

Related threats