Known Exploited Vulnerabilities CVE-2024-49035

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability exploitation_technique T1068 Exploitation for Privilege Escalation
Comments
The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.
References
CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability primary_impact T1530 Data from Cloud Storage
Comments
The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.
References
CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability primary_impact T1195 Supply Chain Compromise
Comments
The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.
References