ZeroHour

CVE-2025-24989

KEVlarge

Access Control Bypass Enables Privilege Escalation in Microsoft Power Pages

CISA: Microsoft Power Pages Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
KEV added
AI analysis

CVE-2025-24989 is a critical (CVSS 9.8) improper access control flaw (CWE-284) in Microsoft Power Pages, Microsoft's low-code cloud service for building external-facing websites. An unauthenticated attacker can trigger it over the network by interacting with an affected Power Pages site, bypassing the user registration control and elevating privileges without any prior credentials or user interaction. Successful exploitation grants elevated access with high impact on the confidentiality, integrity, and availability of the affected site. Only organizations using Power Pages are in scope, and Microsoft has already mitigated the vulnerability in the cloud service and directly notified affected customers - if you were not notified, this vulnerability does not affect you. The flaw was actively exploited before and during patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-21, and carries a 1.6% EPSS probability of exploitation in the next 30 days.

What to do: No customer patch is required because Microsoft applied the fix service-side; review Microsoft's notification and follow its instructions to inspect your Power Pages sites for signs of exploitation (e.g., unexpected or unauthorized users, unusual privilege changes) and perform the recommended cleanup. Federal agencies must apply the vendor mitigations per CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. If you were not notified by Microsoft, the vulnerability does not affect you, though reviewing your site's registration settings is a prudent verification step.

Affected
Microsoft Power PagesCloud service; no specific version numbers disclosed - Microsoft addressed the issue with a service-side mitigation and notified affected customers
Estimated exposure
largeunknown exact count; plausibly tens of thousands of Power Pages sites/tenants (affected subset undisclosed) — Power Pages is a broadly deployed Microsoft cloud service used for customer-facing websites, so the plausibly exposed population is large, but Microsoft did not publish a count of affected tenants and instead notified customers directly,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.

CISA Known Exploited Vulnerability
Affected
Microsoft Power Pages
Required action
Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
power pages
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news