CVE-2024-49035
KEVmass1Unauthenticated Privilege Escalation in Microsoft Partner Center
CISA: Microsoft Partner Center Improper Access Control Vulnerability
An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.
What to do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.
| Microsoft Partner Center (partner.microsoft.com) | Cloud service; no version ranges specified in the data (remediated service-side by Microsoft) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
- Affected
- Microsoft Partner Center
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- partner center
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H