CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-29814

CVSS 9.3v3.1pub. 2025-03-21upd. 2025-07-03

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability results from improper implementation of authorization mechanisms (CWE-20 — improper input validation) in Microsoft Partner Center. An attacker who already has some level of system access can send a properly crafted request over the network that will be processed with higher privileges than appropriate. The network attack vector (AV:N) with no complexity requirements (AC:L) means that the attack can be carried out remotely without special prerequisites, although user interaction is required (UI:R).

Impact

An attacker can obtain elevated privileges in the Microsoft Partner Center environment, leading to serious violations of data integrity and service availability (I:H, A:H according to CVSS vector). The scope of the vulnerability extends beyond the base component (S:C — Changed Scope).

Mitigation & patch

Apply patches available from the vendor according to the references. Detailed information about the update is available in the Microsoft Security Response Center at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29814

Who is affected

Microsoft Partner Center — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
  • Microsoft Partner Center

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-24303CRITICAL9.6PL ✓same product

Privilege Escalation w Microsoft Partner Center przez nieprawidłową kontrolę dostępu

CVE-2025-65041CRITICAL10.0PL ✓same product

Nieprawidłowa autoryzacja w Microsoft Partner Center — privilege escalation

CVE-2024-49035HIGH8.7⚠ KEVsame product

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev...

CVE-2026-69558HIGH8.6same product

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t...

CVE-2026-34327HIGH8.2same product

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthor...