Target Industry
Indiscriminate, opportunistic targeting.
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical Microsoft vulnerability, tracked as CVE-2024-49035. It has been added to the Known Exploited Vulnerabilities (KEV) catalogue, signalling active exploitation in the wild. This update comes a day after CISA added two significant vulnerabilities affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its KEV.
Impact
With a CVSS score of 8.7, CVE-2024-49035 is a severe vulnerability in the Microsoft Partner Centre first reported in November 2024. It allows unauthenticated threat actors to elevate their privileges due to improper access control. This vulnerability affects the online version of Microsoft Power Apps.
Exploitation
The exploitation of CVE-2024-49035 involves a threat actor taking advantage of an improper access control vulnerability in the Microsoft Partner Centre. This allows threat actors to elevate their privileges within the system, granting them access to higher-level functions and data that should be restricted.
Containment, Mitigations & Remediations
To mitigate CVE-2024-49035, Microsoft has implemented automatic fixes through updates to Microsoft Power Apps. It is also recommended to:
- Ensure that all relevant software updates and patches provided by Microsoft are applied promptly
- Review and strengthen access control policies to limit unnecessary permissions and ensure that only authorised users have access to sensitive functions
- Implement robust monitoring and logging to detect any unusual or unauthorised activities within the system.
Threat Landscape
Microsoft acknowledged last year that CVE-2024-49035 had been exploited in the wild. However, it did not disclose whether it had been weaponised in real-world attacks. This vulnerability underscores the need for robust monitoring and advanced security measures to detect and mitigate such sophisticated threats.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













