This is an improper access control vulnerability in Microsoft Partner Center (Partner.Microsoft.com) that allows unauthenticated attackers to elevate privileges over a network. The vulnerability is classified as an 'exclusively-hosted-service' and is actively being exploited in the wild according to CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-11-26
Added to CISA KEV: 2025-02-25 91 DAYS BETWEEN CVE AND KEV
CVE-2024-49035 is an improper access control vulnerability affecting the Microsoft Partner Center (`Partner.Microsoft.com`) [2].
Below is a summary of the known details regarding this vulnerability:
An improper access control vulnerability in Partner.Microsoft.com that allows an unauthenticated attacker to elevate privileges over a network. ... CVE-2024-49035 is an improper access control vulnerability in the Microsoft Partner Center, which has been added to CISA's Known Exploited Vulnerabiliti…
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. ... An official website of the United States government Here's how you know ... Vulnerabilities. CVE-2024-49035 Detail. Exclusively Hosted Service.An improper…
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. ... High severity Unreviewed Published on Nov 26, 2024 to the GitHub Advisory Database • Updated on Oct 21, 2025 ... CVSS v3 base metrics. Attack vector: More…