LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 18, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-49035 to its Known Exploited Vulnerabilities catalog on Feb 25, 2025, with a federal patch deadline of Mar 18, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

CVE-2024-49035 is an improper access control vulnerability in Microsoft Partner Center that allows an attacker to escalate privileges. Microsoft Partner Center is a cloud-based platform used by Microsoft partners for managing customer relationships, licensing, and related business operations. Privilege escalation in this environment can let an unauthorized party gain higher-level access than intended, potentially exposing partner or customer data and administrative functions. Organizations that rely on Partner Center should treat this as a priority for review because cloud services of this type often hold sensitive commercial and identity information.

Public technical detail is limited to the CWE classification and the high-level impact described by CISA. Confirm all version, configuration, and fix specifics against the official Microsoft advisory before acting.

How it works

The vulnerability is classified as CWE-269 (Improper Privilege Management). In this class of flaw, the application fails to enforce correct access-control checks when a user or process requests elevated capabilities. An attacker who already has some level of access—such as a low-privileged partner account—can abuse the missing or incorrect checks to obtain higher privileges inside Partner Center.

Because Partner Center is a multi-tenant cloud service, successful privilege escalation could allow the attacker to view or modify data belonging to other tenants or to perform administrative actions that should be restricted. Exact exploitation steps are not publicly detailed in the provided facts; defenders should assume that any authenticated session that can reach the vulnerable control plane is a potential starting point and must verify the precise attack surface against Microsoft’s advisory.

Am I affected? How to find it in your systems

Microsoft Partner Center is a SaaS offering; it does not run as on-premises software that you install. Any organization that maintains an active Microsoft Partner Center tenant or that grants partner accounts access to customer Microsoft 365 or Azure environments may be in scope.

Because the service is cloud-hosted, traditional network scanning will not detect it. Focus on identity and access-management telemetry rather than host-based indicators. Exact affected configurations must be confirmed against the vendor advisory.

How to remediate

Apply the mitigations published by Microsoft for CVE-2024-49035. CISA’s required action is to follow the vendor instructions, adhere to Binding Operational Directive 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Document the remediation steps and retain evidence of the applied changes for audit purposes.

If you can't patch immediately

Until the vendor mitigation is fully applied, reduce the attack surface with compensating controls appropriate to a cloud privilege-escalation weakness:

If your data may have been exposed

Actively exploited privilege-escalation flaws in cloud management platforms can lead to unauthorized data access or further compromise. Although ransomware use is not documented for this CVE, any successful escalation should be treated as a potential breach. Review Partner Center and Entra ID logs for anomalous activity, force password and session resets for affected accounts, and notify impacted customers according to your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related credentials have appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Partner Center
WeaknessCWE-269
Added to CISA KEVFeb 25, 2025
Federal patch deadlineMar 18, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities