Article Details
Scrape Timestamp (UTC): 2024-11-29 09:36:48.105
Source: https://thehackernews.com/2024/11/microsoft-fixes-ai-cloud-and-erp.html
Original Article Text
Click to Toggle View
Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks. Microsoft has addressed four security flaws impacting its artificial intelligence (AI), cloud, enterprise resource planning, and Partner Center offerings, including one that it said has been exploited in the wild. The vulnerability that has been tagged with an "Exploitation Detected" assessment is CVE-2024-49035 (CVSS score: 8.7), a privilege escalation flaw in partner.microsoft[.]com. "An improper access control vulnerability in partner.microsoft[.]com allows an unauthenticated attacker to elevate privileges over a network," the tech giant said in an advisory released this week. Microsoft credited Gautam Peri, Apoorv Wadhwa, and an anonymous researcher for reporting the flaw, but did not reveal any specifics on how it's being exploited in real-world attacks. Fixes for the shortcomings are being rolled out automatically as part of updates to the online version of Microsoft Power Apps. Also addressed by Redmond are three other vulnerabilities, two of which are rated Critical and one is rated Important in severity - While most of the vulnerabilities have already been fully mitigated and require no user action, it's advised to update Dynamics 365 Sales apps for Android and iOS to the latest version (3.24104.15) to secure against CVE-2024-49053.
Daily Brief Summary
Microsoft has resolved four security vulnerabilities affecting its AI, cloud, ERP, and Partner Center services.
One of the patched vulnerabilities, tagged as CVE-2024-49035, was actively exploited and involved unauthenticated privilege escalation at partner.microsoft[.]com.
This particular vulnerability had a high severity score of 8.7 and allowed attackers to escalate network privileges without authentication.
The flaw was discovered and reported by Gautam Peri, Apoorv Wadhwa, and an unidentified researcher.
Fixes for these vulnerabilities are being implemented automatically in updates to Microsoft Power Apps.
Additional vulnerabilities rated Critical and Important were also addressed but require users to update their Dynamics 365 Sales apps on Android and iOS to the latest versions.
Microsoft has not disclosed specifics on the real-world exploitation tactics or the impact of these vulnerabilities.