Microsoft has fixed a security flaw in its Power Pages website-building SaaS, after criminals got there first – and urged users to check their sites for signs of exploitation. Power Pages is part of Microsoft's low-code Power Platform suite and offers tools to create, host, and update business websites. The newly patched flaw, CVE-2025-24989, technically speaking allows attackers to elevate privileges over a network, potentially bypassing the user registration control. In plainer English: Unauthorized miscreants could use the hole to log into sites using accounts they shouldn't have. Power Pages is software-as-a-service, so Microsoft has closed the vulnerability at its end. The software giant has nonetheless sent affected customers instructions on how to review their sites for signs of potential exploitation, and procedures to clean up if needed. The good news is that this problem doesn’t impact all Power Pages users. “If you've not been notified, this vulnerability does not affect you,” states Microsoft’s advisory. Microsoft staffer Raj Kumar spotted the flaw, which was rated 8.2 out of 10 on the CVSS scale. Redmond warned that attackers had already taken advantage of the flaw before it implemented the fix. Power Pages was introduced in 2022, and Microsoft claims it has over 250 million monthly active website users. One of them is Britain's National Health Service, which last year exposed data describing over a million of its staff due to misconfigured access controls in web...
Microsoft Power Pages websites attacked via security hole
The Register
·Iain Thomson
·Published Feb 20, 2025
·Updated
Affected Software
3 affected components
Microsoft Power Pages
Microsoft Bing
Microsoft Power Pages
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in Microsoft Power Pages that has been exploited by attackers before Microsoft issued a patch.
2
What security implications are discussed?
The article highlights the risks of unauthorized access and potential data breaches due to the exploited flaw in Power Pages.
3
What products or software are affected?
The affected software mentioned in the article is Microsoft Power Pages, which is part of Microsoft’s low-code Power Platform suite.
4
What actions are users advised to take following this security issue?
Users are urged to check their Power Pages sites for signs of exploitation and apply the security patch provided by Microsoft.
5
Who provided the security update for this vulnerability?
Microsoft addressed the security flaw by releasing a patch for Power Pages after the exploit was discovered.