Microsoft Patches Critical Security Flaws, Including One Actively Exploited The company credited researchers Gautam Peri, Apoorv Wadhwa, and an anonymous contributor for reporting the issue

By BIZ Experiences Staff

You're reading BIZ Experiences India, an international franchise of BIZ Experiences Media.

Freepik

Microsoft has addressed four major security vulnerabilities affecting its artificial intelligence (AI), cloud, enterprise resource planning, and Partner Center services. One of the vulnerabilities, identified as CVE-2024-49035 and carrying a severity score of 8.7, has already been exploited in the wild. This privilege escalation flaw in Microsoft's Partner Center platform allows attackers to gain unauthorized elevated access over a network. The company credited researchers Gautam Peri, Apoorv Wadhwa, and an anonymous contributor for reporting the issue but has not disclosed details of its real-world exploitation. Fixes for this vulnerability are being applied automatically.

In addition to CVE-2024-49035, Microsoft has resolved three other vulnerabilities. Two are classified as critical: CVE-2024-49038, a cross-site scripting (XSS) flaw in Copilot Studio with a severity score of 9.3, and CVE-2024-49052, a missing authentication issue in Microsoft Azure PolicyWatch rated at 8.2. Both could allow attackers to escalate privileges over a network. The third, CVE-2024-49053, is a spoofing vulnerability in Dynamics 365 Sales, with a score of 7.6. This flaw could enable attackers to redirect users to malicious websites via specially crafted URLs.

While most of these vulnerabilities have been automatically mitigated, Microsoft advises users of Dynamics 365 Sales apps on Android and iOS to update to version 3.24104.15 to protect against CVE-2024-49053. The company continues to roll out updates to safeguard its platforms, urging users to remain vigilant and apply recommended patches to maintain security.


BIZ Experiences Staff

BIZ Experiences Staff

Editor

For more than 30 years, BIZ Experiences has set the course for success for millions of BIZ Experiencess and small business owners. We'll teach you the secrets of the winners and give you exactly what you need to lay the groundwork for success.
Business News

AI Will Create More Millionaires in the Next 5 Years Than the Internet Did in 2 Decades, According to Nvidia's CEO

Nvidia CEO Jensen Huang said that AI enables people to create new things, generating more opportunities to produce revenue.

Money & Finance

Why Your Inner Voice Might Be Sabotaging Your Trading Strategy

Don't sabotage your own trading career with negative self-talk.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for BIZ Experiencess to pursue in 2025.

Marketing

How to Make Sure ChatGPT Recommends Your Products — Not Your Competitor's

AI is changing how people shop — if you're still relying on SEO, you're already behind. Optimize for AI to stay visible.

News and Trends

Reliance Retail Launches FMCG Brand 'Independence' In Gujarat

Independence includes diverse categories such as staples, processed foods, beverages, among other daily essentials

Business Models

How Digitally Organized Teams Can Outpace Companies 100x Their Size

Digital organization helps prevent trust-eroding moments and helps small businesses avoid drowning in too much data overload.