{"cveID":"CVE-2024-49035","vendorProject":"Microsoft","product":"Partner Center","vulnerabilityName":"Microsoft Partner Center Improper Access Control Vulnerability","dateAdded":"2025-02-25","shortDescription":"Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-03-18","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49035 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49035","cwes":["CWE-269"],"year":2024,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2024-49035","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"exploitation_technique","capability_group":"access_ctrl","comments":"The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.","references":["https://op-c.net/blog/microsoft-partner-center-vulnerability-cve-2024-49035/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-49035","technique":"T1195","technique_name_at_mapping":"Supply Chain Compromise","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.","references":["https://op-c.net/blog/microsoft-partner-center-vulnerability-cve-2024-49035/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-49035","technique":"T1530","technique_name_at_mapping":"Data from Cloud Storage","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"The details of this exploit are not publicly disclosed, but due to improper access controls in the Microsoft Power Apps backend, attackers can potentially escalate their privileges, affecting the Partner Center web portal and putting the data stored there at risk.","references":["https://op-c.net/blog/microsoft-partner-center-vulnerability-cve-2024-49035/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1195","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Supply Chain Compromise","name_at_mapping":"Supply Chain Compromise","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":1,"has_detection_strategy":true},{"id":"T1530","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Cloud Storage","name_at_mapping":"Data from Cloud Storage","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}