🔴 CVE-2024-49035

This is an improper access control vulnerability in Microsoft Partner Center (Partner.Microsoft.com) that allows unauthenticated attackers to elevate privileges over a network. The vulnerability is classified as an 'exclusively-hosted-service' and is actively being exploited in the wild according to CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
8.7
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2024-11-26

Added to CISA KEV: 2025-02-25 91 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2024-49035 is an improper access control vulnerability affecting the Microsoft Partner Center (`Partner.Microsoft.com`) [2].

Below is a summary of the known details regarding this vulnerability:

Vulnerability Overview
  • Impact: The vulnerability allows an unauthenticated attacker to elevate privileges over a network [2].
  • Attack Method: It is a network-based attack that does not require authentication or user interaction to exploit [3].
Exploitation and Threat Activity
  • Active Exploitation: This vulnerability has been confirmed as being actively exploited in the wild. It was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog due to evidence of such activity [1].
  • Targeted Attacks/Ransomware: While it is confirmed to be exploited in the wild, specific details regarding its use in ransomware campaigns or specific targeted threat actor groups are not publicly detailed in standard vulnerability databases.
Availability of Exploits and Mitigations
  • Proof-of-Concept (PoC): There is no widely available public information detailing specific proof-of-concept exploit code or tools for this vulnerability [1].
  • Affected Versions and Patch Status: The vulnerability affects the Microsoft Partner Center. Because this is a hosted service managed by Microsoft, remediation is typically handled on the server side by the vendor. Users of the service should follow guidance provided by Microsoft's Security Response Center (MSRC) regarding any necessary actions or updates [1].

Sources

  1. CVE-2024-49035 - Exploits & Severity

    An improper access control vulnerability in Partner.Microsoft.com that allows an unauthenticated attacker to elevate privileges over a network. ... CVE-2024-49035 is an improper access control vulnerability in the Microsoft Partner Center, which has been added to CISA's Known Exploited Vulnerabiliti…

  2. CVE-2024-49035 Detail - NVD

    An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. ... An official website of the United States government Here's how you know ... Vulnerabilities. CVE-2024-49035 Detail. Exclusively Hosted Service.An improper…

  3. An improper access control vulnerability in Partner... · CVE- ...

    An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. ... High severity Unreviewed Published on Nov 26, 2024 to the GitHub Advisory Database • Updated on Oct 21, 2025 ... CVSS v3 base metrics. Attack vector: More…