U.S. CISA adds Microsoft Power Pages flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24989 | Access Control Bypass Enables Privilege Escalation in Microsoft Power Pages CVE-2025-24989 is a critical (CVSS 9.8) improper access control flaw (CWE-284) in Microsoft Power Pages, Microsoft's low-code cloud service for building external-facing websites. An unauthenticated attacker can trigger it over the network by interacting with an affected Power Pages site, bypassing the user registration control and elevating privileges without any prior credentials or user interaction. Successful exploitation grants elevated access with high impact on the confidentiality, integrity, and availability of the affected site. Only organizations using Power Pages are in scope, and Microsoft has already mitigated the vulnerability in the cloud service and directly notified affected customers - if you were not notified, this vulnerability does not affect you. The flaw was actively exploited before and during patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-21, and carries a 1.6% EPSS probability of exploitation in the next 30 days. Do: No customer patch is required because Microsoft applied the fix service-side; review Microsoft's notification and follow its instructions to inspect your Power Pages sites for signs of exploitation (e.g., unexpected or unauthorized users, unusual privilege changes) and perform the recommended cleanup. Federal agencies must apply the vendor mitigations per CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. If you were not notified by Microsoft, the vulnerability does not affect you, though reviewing your site's registration settings is a prudent verification step. | 9.8 | 2% | KEV |
| largeunknown exact count; plausibly tens of thousands of Power Pages sites/tenants (affected subset undisclosed) |
Full article222 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 23, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Power Pages vulnerability to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft Power Pages vulnerability, tracked as CVE-2025-24989, to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2025-24989 (CVSS score: 8.2) is an improper access control flaw in Power Pages, an unauthorized attacker could exploit the flaw to elevate privileges over a network potentially bypassing the user registration control.
Raj Kumar with Microsoft reported the vulnerability. This week Microsoft addressed it and confirmed that this vulnerability is actively exploited in the wild.
“Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you’ve not been notified this vulnerability does not affect you.” reads the advisory published by Microsoft.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by March 21, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, privilege escalation)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174541/hacking/u-s-cisa-adds-microsoft-power-pages-flaw-known-exploited-vulnerabilities-catalog.html