• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-fixes-power-pages-zero-day-bug-exploited-in-attacks/

Microsoft fixes Power Pages zero-day bug exploited in attacks

BleepingComputer
·
Bill Toulas
·
Published Feb 20, 2025
·
Updated

Microsoft has issued a security bulletin for a high-severity elevation of privilege vulnerability in Power Pages, which hackers exploited as a zero-day in attacks. The flaw, tracked as CVE-2025-24989, is an improper access control problem impacting Power Pages, allowing unauthorized actors to elevate their privileges over a network and bypass user registration controls. Microsoft says it has addressed the risk at the service level and notified impacted customers accordingly, enclosing instructions on how to detect potential compromise. "This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass," reads Microsoft's security bulletin. "Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you." Microsoft Power Pages is a low-code, SaaS-based web development platform that allows users to create, host, and manage secure external-facing business websites. It is part of the Microsoft Power Platform, which includes tools like Power BI, Power Apps, and Power Automate. Since Power Pages is a cloud-based service, it can be assumed that exploitation occurred remotely. The software giant has not provided details about how the flaw was exploited in attacks. In addition to the Power Pages flaw, Microsoft also fixed a Bing remote code execution vulnerability y...

Read full article

Affected Software

2 affected components
Microsoft Power Pages
Microsoft Power Pages
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Microsoft fixing a high-severity elevation of privilege vulnerability in Power Pages that has been exploited as a zero-day in attacks.

2

What security implications are discussed in the article?

The article highlights the risks associated with the zero-day vulnerability, which can allow unauthorized users to elevate their privileges and perform malicious actions.

3

What products or software are affected by the vulnerability?

The vulnerability affects Microsoft Power Pages, specifically identified as CVE-2025-24989.

4

How was the vulnerability discovered?

The article mentions that the zero-day was actively exploited in the wild before Microsoft released the security patch.

5

What steps has Microsoft taken to address the issue?

Microsoft has issued a security bulletin and released a patch to fix the elevation of privilege vulnerability in Power Pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203