VDB
CVE-2024-49035
CVE-2024-49035
PUBLISHED
KEV
CVSS 8.699999809265137 HIGH
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
EPSS 5.51% · 90.4th percentile
Risk Scores
CVSS v3.1
8.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
EPSS Score
5.51%
90.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | partner_center | N/A |
| Microsoft | Microsoft Partner Center | N/A |
Timeline
- Nov 12, 2024 CVE Published
- Nov 26, 2024 PoC Published
- Nov 26, 2024 PoC Published
- Nov 27, 2024 EPSS Score
- Nov 27, 2024 PoC Published
- Nov 28, 2024 PoC Published
- Nov 29, 2024 PoC Published
- Nov 29, 2024 PoC Published
- Jan 1, 2025 EPSS Score
- Jan 18, 2025 EPSS Score
- Feb 20, 2025 Coalition ESS Score
- Feb 22, 2025 EPSS Score
References
- Partner.Microsoft.Com Elevation of Privilege Vulnerability vendor-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-49035 url
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49053 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49038 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-49035 advisory