peter bassill · operator
$ cve CVE-2024-49035 JSON

CVE-2024-49035 KEV

8.7
HIGH · CVSS 3.1 · EPSS 1.3% (pctl 69)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-18.

Description

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Scoring

CVSS8.7 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
EPSS1.3% — more likely to be exploited than 69% of all CVEs
WeaknessCWE-269
On CISA KEVyes — remediate by 2025-03-18
Public exploitnone known
Published2024-11-26
Last modified2026-06-17

CISA KEV

NameMicrosoft Partner Center Improper Access Control Vulnerability
Added2025-02-25
Due2025-03-18
Vendor / productMicrosoft / Partner Center
Ransomware usenone reported

Affected (1)

VendorProduct
microsoftpartner center

References

→ the Explorer  ·  watch your stack  ·  NVD