Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
The vulnerability results from improper implementation of authorization mechanisms (CWE-20 — improper input validation) in Microsoft Partner Center. An attacker who already has some level of system access can send a properly crafted request over the network that will be processed with higher privileges than appropriate. The network attack vector (AV:N) with no complexity requirements (AC:L) means that the attack can be carried out remotely without special prerequisites, although user interaction is required (UI:R).
An attacker can obtain elevated privileges in the Microsoft Partner Center environment, leading to serious violations of data integrity and service availability (I:H, A:H according to CVSS vector). The scope of the vulnerability extends beyond the base component (S:C — Changed Scope).
Apply patches available from the vendor according to the references. Detailed information about the update is available in the Microsoft Security Response Center at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29814
Microsoft Partner Center — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:HMicrosoft Partner Center
APPMicrosoftall versions
Related vulnerabilities
Privilege Escalation w Microsoft Partner Center przez nieprawidłową kontrolę dostępu
Nieprawidłowa autoryzacja w Microsoft Partner Center — privilege escalation
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev...
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t...
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthor...