CVE-2025-24989: Microsoft Power Pages Improper Access Control Vulnerability
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.
Other sources
Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
— CISA
Microsoft Power Pages Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24989?
The CVE-2025-24989 vulnerability is classified as a serious security threat due to its potential for unauthorized privilege escalation.
How do I fix CVE-2025-24989?
CVE-2025-24989 has already been mitigated in the service, so affected customers do not need to take action at this time.
What is the impact of CVE-2025-24989?
CVE-2025-24989 allows unauthorized attackers to potentially bypass user registration controls and elevate their privileges over the network.
Is there a patch for CVE-2025-24989?
As CVE-2025-24989 has been mitigated by Microsoft, there is no need for a separate patch for affected users.
Who is affected by CVE-2025-24989?
Users of Microsoft Power Pages may have been affected by the CVE-2025-24989 vulnerability.