First published: Wed Feb 19 2025(Updated: )
<p>An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.</p> <p>This vulnerability <strong>has already been mitigated in the service</strong> and all affected cusomters have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Power Pages |
Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2025-24989 vulnerability is classified as a serious security threat due to its potential for unauthorized privilege escalation.
CVE-2025-24989 has already been mitigated in the service, so affected customers do not need to take action at this time.
CVE-2025-24989 allows unauthorized attackers to potentially bypass user registration controls and elevate their privileges over the network.
As CVE-2025-24989 has been mitigated by Microsoft, there is no need for a separate patch for affected users.
Users of Microsoft Power Pages may have been affected by the CVE-2025-24989 vulnerability.