ZeroHour

CVE-2024-49035

KEVmass1

Unauthenticated Privilege Escalation in Microsoft Partner Center

CISA: Microsoft Partner Center Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
KEV added
AI analysis

An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.

What to do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.

Affected
Microsoft Partner Center (partner.microsoft.com)Cloud service; no version ranges specified in the data (remediated service-side by Microsoft)
Estimated exposure
masshundreds of thousands of partner organizations (Microsoft's partner ecosystem is commonly cited at 400k+ partners); exact account/user counts undisclosed — Partner.Microsoft.com is a single internet-exposed Microsoft cloud service serving Microsoft's large global partner/CSP ecosystem and, through it, the customer tenants those partners manage, so plausible exposure is at the mass scale — an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

CISA Known Exploited Vulnerability
Affected
Microsoft Partner Center
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
partner center
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news