CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
Other sources
Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.
— CISA
Partner.Microsoft.Com Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49035?
CVE-2024-49035 has been rated as a high severity vulnerability due to its potential for unauthorized privilege escalation.
How do I fix CVE-2024-49035?
To mitigate CVE-2024-49035, ensure that your Microsoft Partner Center is updated to the latest version that addresses this access control issue.
Who is affected by CVE-2024-49035?
CVE-2024-49035 affects users and administrators of Microsoft Partner Center who do not have proper access control configurations.
Can an attacker exploit CVE-2024-49035 remotely?
Yes, an unauthenticated attacker can exploit CVE-2024-49035 over a network to elevate privileges.
What kind of attacks are associated with CVE-2024-49035?
CVE-2024-49035 can facilitate attacks such as privilege escalation, allowing attackers to gain unauthorized access to sensitive functions within Partner.Microsoft.com.