Executive brief
Microsoft Partner Center (Partner.Microsoft.com) contains an improper access control vulnerability that allows an unauthenticated attacker to elevate privileges over a network. The flaw is tracked as CVE-2024-49035 and has been observed being exploited in the wild.
Affected products
- Microsoft Partner Center Partner.Microsoft.com
Timeline
- 2024-11-26: disclosed: NVD Published Date and initial receipt from Microsoft
- 2025-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-25: exploited: Reported as exploited in the wild in advisory metadata