Executive brief
Microsoft Power Pages contains an improper access control vulnerability that allows an unauthenticated attacker to bypass user registration controls and elevate privileges over a network. The vulnerability has been exploited in the wild and was mitigated by Microsoft via service-side updates. Affected customers were notified directly with instructions for reviewing potential exploitation and performing cleanup.
Affected products
- Microsoft Power Pages -
Timeline
- 2025-02-19: disclosed: NVD Published Date
- 2025-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-21: patched: Microsoft confirmed the vulnerability was mitigated in the service.