Microsoft fixed actively exploited flaw in Power Pages
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21355 | Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2025-24989 | Access Control Bypass Enables Privilege Escalation in Microsoft Power Pages CVE-2025-24989 is a critical (CVSS 9.8) improper access control flaw (CWE-284) in Microsoft Power Pages, Microsoft's low-code cloud service for building external-facing websites. An unauthenticated attacker can trigger it over the network by interacting with an affected Power Pages site, bypassing the user registration control and elevating privileges without any prior credentials or user interaction. Successful exploitation grants elevated access with high impact on the confidentiality, integrity, and availability of the affected site. Only organizations using Power Pages are in scope, and Microsoft has already mitigated the vulnerability in the cloud service and directly notified affected customers - if you were not notified, this vulnerability does not affect you. The flaw was actively exploited before and during patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-21, and carries a 1.6% EPSS probability of exploitation in the next 30 days. Do: No customer patch is required because Microsoft applied the fix service-side; review Microsoft's notification and follow its instructions to inspect your Power Pages sites for signs of exploitation (e.g., unexpected or unauthorized users, unusual privilege changes) and perform the recommended cleanup. Federal agencies must apply the vendor mitigations per CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. If you were not notified by Microsoft, the vulnerability does not affect you, though reviewing your site's registration settings is a prudent verification step. | 9.8 | 2% | KEV |
| largeunknown exact count; plausibly tens of thousands of Power Pages sites/tenants (affected subset undisclosed) |
Full article176 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 20, 2025

Microsoft addressed a privilege escalation vulnerability in Power Pages, the flaw is actively exploited in attacks.
Microsoft has addressed two critical vulnerabilities, tracked as CVE-2025-21355 (CVSS score: 8.6) and CVE-2025-24989 (CVSS score: 8.2), respectively impacting Bing and Power Pages.
CVE-2025-21355 is a missing authentication for critical Function in Microsoft Bing, an unauthorized attacker could exploit the flaw to execute code over a network. The researcher Nicolas Joly reported the vulnerability.
CVE-2025-24989 is an improper access control flaw in Power Pages, an unauthorized attacker could exploit the flaw to elevate privileges over a network potentially bypassing the user registration control.
Raj Kumar with Microsoft reported the vulnerability. The IT giant confirmed that this vulnerability is actively exploited in the wild.
“Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you’ve not been notified this vulnerability does not affect you.” reads the advisory published by Microsoft.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, privilege escalation)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174430/security/microsoft-fixed-actively-exploited-flaw-in-power-pages.html