ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49035
Unauthenticated Privilege Escalation in Microsoft Partner Center

An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.

Do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.

9.81% KEV
  • Microsoft Partner Center (partner.microsoft.com) Cloud service; no version ranges specified in the data (remediated service-side by Microsoft)
masshundreds of thousands of partner organizations (Microsoft's partner ecosystem is commonly cited at 400k+ partners); exact account/user counts undisclosed
CVE-2024-49038
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privile

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

NVD description · AI analysis pending
9.6<1%
  • microsoft copilot studio
CVE-2024-49052
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

NVD description · AI analysis pending
9.8<1%
  • microsoft azure functions
CVE-2024-49053
Microsoft Dynamics 365 Sales Spoofing Vulnerability

Microsoft Dynamics 365 Sales Spoofing Vulnerability

NVD description · AI analysis pending
7.6<1%
  • microsoft dynamics 365 sales

Indicators of compromiseAll →

TypeIndicatorContext
domainmicrosoft.com5 (CVSS score: 8.7), a privilege escalation flaw in partner.microsoft[.]com. "An improper access control vulnerability in partner.mic
Full article311 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 29, 2024AI Security / Cloud Security

Microsoft has addressed four security flaws impacting its artificial intelligence (AI), cloud, enterprise resource planning, and Partner Center offerings, including one that it said has been exploited in the wild.

The vulnerability that has been tagged with an "Exploitation Detected" assessment is CVE-2024-49035 (CVSS score: 8.7), a privilege escalation flaw in partner.microsoft[.]com.

"An improper access control vulnerability in partner.microsoft[.]com allows an unauthenticated attacker to elevate privileges over a network," the tech giant said in an advisory released this week.

Microsoft credited Gautam Peri, Apoorv Wadhwa, and an anonymous researcher for reporting the flaw, but did not reveal any specifics on how it's being exploited in real-world attacks.

Fixes for the shortcomings are being rolled out automatically as part of updates to the online version of Microsoft Power Apps. Also addressed by Redmond are three other vulnerabilities, two of which are rated Critical and one is rated Important in severity -

  • CVE-2024-49038 (CVSS score: 9.3) - A cross-site scripting (XSS) vulnerability in Copilot Studio that could allow an unauthorized attacker to escalate privileges over a network
  • CVE-2024-49052 (CVSS score: 8.2) - A missing authentication for a critical function vulnerability in Microsoft Azure PolicyWatch that could allow an unauthorized attacker to escalate privileges over a network
  • CVE-2024-49053 (CVSS score: 7.6) - A spoofing vulnerability in Microsoft Dynamics 365 Sales that could allow an authenticated attacker to trick a user into clicking on a specially crafted URL and potentially redirect the victim to a malicious site

While most of the vulnerabilities have already been fully mitigated and require no user action, it's advised to update Dynamics 365 Sales apps for Android and iOS to the latest version (3.24104.15) to secure against CVE-2024-49053.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/microsoft-fixes-ai-cloud-and-erp.html