• News/
  • https://www.theregister.com/2025/02/20/microsoft_patch_power_pages/

Microsoft Power Pages websites attacked via security hole

The Register
·
Iain Thomson
·
Published Feb 20, 2025
·
Updated

Microsoft has fixed a security flaw in its Power Pages website-building SaaS, after criminals got there first – and urged users to check their sites for signs of exploitation. Power Pages is part of Microsoft's low-code Power Platform suite and offers tools to create, host, and update business websites. The newly patched flaw, CVE-2025-24989, technically speaking allows attackers to elevate privileges over a network, potentially bypassing the user registration control. In plainer English: Unauthorized miscreants could use the hole to log into sites using accounts they shouldn't have. Power Pages is software-as-a-service, so Microsoft has closed the vulnerability at its end. The software giant has nonetheless sent affected customers instructions on how to review their sites for signs of potential exploitation, and procedures to clean up if needed. The good news is that this problem doesn’t impact all Power Pages users. “If you've not been notified, this vulnerability does not affect you,” states Microsoft’s advisory. Microsoft staffer Raj Kumar spotted the flaw, which was rated 8.2 out of 10 on the CVSS scale. Redmond warned that attackers had already taken advantage of the flaw before it implemented the fix. Power Pages was introduced in 2022, and Microsoft claims it has over 250 million monthly active website users. One of them is Britain's National Health Service, which last year exposed data describing over a million of its staff due to misconfigured access controls in web...

Read full article

Affected Software

3 affected components
Microsoft Power Pages
Microsoft Bing
Microsoft Power Pages
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in Microsoft Power Pages that has been exploited by attackers before Microsoft issued a patch.

2

What security implications are discussed?

The article highlights the risks of unauthorized access and potential data breaches due to the exploited flaw in Power Pages.

3

What products or software are affected?

The affected software mentioned in the article is Microsoft Power Pages, which is part of Microsoft’s low-code Power Platform suite.

4

What actions are users advised to take following this security issue?

Users are urged to check their Power Pages sites for signs of exploitation and apply the security patch provided by Microsoft.

5

Who provided the security update for this vulnerability?

Microsoft addressed the security flaw by releasing a patch for Power Pages after the exploit was discovered.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203