Microsoft Power Pages contains an improper access control vulnerability that allows unauthorized attackers to elevate privileges over a network, potentially bypassing user registration controls. This vulnerability is actively exploited in the wild and affects a cloud-based web application platform that is inherently internet-facing.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-02-19
Added to CISA KEV: 2025-02-21 2 DAYS BETWEEN CVE AND KEV
CVE-2025-24989 is an improper access control vulnerability affecting Microsoft Power Pages that was identified and addressed in February 2025 [1] [2].
Below is a summary of the known details regarding this vulnerability:
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only onβ¦
The vulnerability, tracked as CVE-2025-24989, is an improper access control problem that allows unauthorized actors to elevate their privileges over a network and bypass user registration controls. Microsoft has addressed the risk at the service level and notified impacted customers, but users shoulβ¦
A high severity vulnerability in Power Pages allows an unauthorized attacker to bypass user registration control. The vulnerability has been mitigated and affected customers have been notified and instructed to review their sites.
The vulnerability, listed as CVE-2025-24989, is an improper access control flaw that allows privilege escalation in Microsoft Power Pages.