CVE-2025-24989
Microsoft Power Pages Elevation of Privilege Vulnerability
In short
Microsoft Power Pages has a flaw in its access control that lets attackers gain higher privileges over the network and bypass user registration restrictions. This means unauthorized people could gain access they shouldn't have.
Technical detail
An improper access control vulnerability in Power Pages allows remote attackers to elevate privileges by bypassing registration control mechanisms. The vulnerability stems from insufficient authorization checks on privilege escalation endpoints, enabling unauthenticated or low-privileged users to access restricted functionality without proper validation.
Summary generated and translated by AI from the official description.
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft Power PagesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →