KEVIntel
8.7
CVSS
High

CVE-2024-49035

PUBLISHED

Partner.Microsoft.Com Elevation of Privilege Vulnerability

Exploited in the wild Remote Low complexity
Vendor
Microsoft
Product
Microsoft Partner Center
Published
Nov 26, 2024
EPSS

Description

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

cisa microsoft

CVSS scores

CVSS v3.1 8.7 High

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C

Exploitation status

Exploited in the wild

Recorded 2025-02-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 25, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel