Microsoft Patches Critical Security Flaws, Including One Actively Exploited The company credited researchers Gautam Peri, Apoorv Wadhwa, and an anonymous contributor for reporting the issue

By Entrepreneur Staff

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Freepik

Microsoft has addressed four major security vulnerabilities affecting its artificial intelligence (AI), cloud, enterprise resource planning, and Partner Center services. One of the vulnerabilities, identified as CVE-2024-49035 and carrying a severity score of 8.7, has already been exploited in the wild. This privilege escalation flaw in Microsoft's Partner Center platform allows attackers to gain unauthorized elevated access over a network. The company credited researchers Gautam Peri, Apoorv Wadhwa, and an anonymous contributor for reporting the issue but has not disclosed details of its real-world exploitation. Fixes for this vulnerability are being applied automatically.

In addition to CVE-2024-49035, Microsoft has resolved three other vulnerabilities. Two are classified as critical: CVE-2024-49038, a cross-site scripting (XSS) flaw in Copilot Studio with a severity score of 9.3, and CVE-2024-49052, a missing authentication issue in Microsoft Azure PolicyWatch rated at 8.2. Both could allow attackers to escalate privileges over a network. The third, CVE-2024-49053, is a spoofing vulnerability in Dynamics 365 Sales, with a score of 7.6. This flaw could enable attackers to redirect users to malicious websites via specially crafted URLs.

While most of these vulnerabilities have been automatically mitigated, Microsoft advises users of Dynamics 365 Sales apps on Android and iOS to update to version 3.24104.15 to protect against CVE-2024-49053. The company continues to roll out updates to safeguard its platforms, urging users to remain vigilant and apply recommended patches to maintain security.


Entrepreneur Staff

Entrepreneur Staff

Editor

For more than 30 years, Entrepreneur has set the course for success for millions of entrepreneurs and small business owners. We'll teach you the secrets of the winners and give you exactly what you need to lay the groundwork for success.
Business News

What's Open on Easter Sunday? Costco and Target Will Close, But One Major Retailer Will Be Open. Here's What To Know.

The stock market was closed for Good Friday on April 18. Here's what's closed for Easter Sunday, April 20.

Marketing

The One Mistake Is Putting Your Brand Reputation at Risk — and Most Startups Still Make It

Many businesses pour resources into branding and marketing but overlook PR — yet it's PR that builds the trust, credibility, and reputation that turn attention into lasting revenue in a crowded market.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Side Hustle

This Couple Started a Side Hustle to Improve a 'Terribly Made' Bathroom Essential. Now the Business Earns More Than $3 Million a Year.

Michael Fine and Lisa Schulner-Fine launched lifestyle brand Quiet Town in 2016 and have been growing it ever since.

News and Trends

Kolkata-Based Lab-Grown Diamond Brand Jewelbox Secures USD 3.2 Mn

The startup will primarily use the funds to expand its retail footprint, growing from eight stores to 30 locations by the end of this year.

Business News

Want to Be the Next CEO of Jack in the Box? You Have to Be Really Good at Fortnite.

The fast food giant and Fortnite have a simple question: Do you have what it takes to be Jack in the Box's next CEO?