CVE-2024-49035

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

  • Published Nov 26, 2024
  • CVSS 9.8 critical
  • 1.3% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2024-49035 at the National Vulnerability Database