CRITICAL

CVE-2025-24989

Microsoft Power Pages 2025-02-19 CVSS v3.1
CVSS
9.8
KEV

Description

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.

Summary dbcve.org

Improper access control vulnerability in Microsoft Power Pages allows unauthenticated attackers to elevate privileges by bypassing user registration controls. This enables unauthorized network-based access with elevated permissions.

Mitigation

Microsoft has already mitigated this vulnerability in the service. Affected customers who were notified should follow Microsoft's instructions to review their sites for signs of exploitation and perform necessary cleanup actions.

Patch Commit

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

1.62%
Probability of exploitation in next 30 days
75th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE