Junglewise Threat Intelligence

CVE-2025-24989: Microsoft Power Pages Improper Access Control Vulnerability

CVE-2025-24989 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-02-21

Vendors: Microsoft.

Executive brief

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthenticated attacker to bypass user registration controls and elevate privileges over a network. The vulnerability has been exploited in the wild and was mitigated by Microsoft via service-side updates. Affected customers were notified directly with instructions for reviewing potential exploitation and performing cleanup.

Affected products

  • Microsoft Power Pages -

Timeline

  • 2025-02-19: disclosed: NVD Published Date
  • 2025-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-21: patched: Microsoft confirmed the vulnerability was mitigated in the service.

Related threats