CVE-2024-49035CISA KEV
Microsoft Partner Center Improper Access Control Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.
- Product
- Partner Center
- Added to KEV
- 25 Feb 2025
- Federal remediation due
- 18 Mar 2025
- Known ransomware use
- Not reported