← Vulnerability feed

Vulnerability record · CVE-2025-24989 · published 19 February 2025

CVE-2025-24989: Microsoft Power Pages improper access control allows privilege elevation

Microsoft · Power Pages

Power Pages contains an improper access control flaw that lets an unauthorized network attacker elevate privileges, potentially bypassing the user registration control. Microsoft states the vulnerability has already been mitigated in the service and affected customers were notified, so this record describes a service-side fix rather than a customer-applied patch.

9.8 CVSS 3.1 Critical CISA KEV since 21 Feb 2025 EPSS 1.6% · top 24.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, plus confirmed exploitation in the CISA KEV catalog, makes this a top remediation priority despite the low EPSS score.

What it is

Power Pages contains an improper access control flaw that lets an unauthorized network attacker elevate privileges, potentially bypassing the user registration control. Microsoft states the vulnerability has already been mitigated in the service and affected customers were notified, so this record describes a service-side fix rather than a customer-applied patch.

Impact

An unauthenticated attacker can bypass registration controls and elevate privileges, gaining high confidentiality, integrity and availability impact on the affected site. This can expose or corrupt site data and allow unauthorized administrative-level actions.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the Power Pages service itself, so any exposed site using the affected registration control is a potential target.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-21, indicating known exploitation in the wild. EPSS is low at roughly 1.6% (74.9th percentile), but the KEV listing and vendor notification of affected customers outweigh that signal.

What to do

  • Confirm whether Microsoft notified you as an affected customer; if not, the vendor states you are not affected.
  • Apply the service-side mitigation Microsoft already deployed and follow the vendor's remediation guidance.
  • Review Power Pages sites for signs of unauthorized registration or privilege changes and perform the cleanup steps Microsoft provided.
  • If mitigations are unavailable, follow BOD 22-01 guidance for cloud services or discontinue use of the product.
  • Track the CISA KEV due date of 2025-03-14 for federal remediation timelines.

Detection

  • Audit Power Pages registration and authentication logs for accounts created outside expected registration flows.
  • Review site user and role assignments for unexpected privilege grants or new administrative accounts.
  • Monitor for anomalous access patterns to Power Pages sites that bypass normal registration controls.
  • Compare current site configuration and user lists against known-good baselines to spot unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-24989 to the Known Exploited Vulnerabilities catalog on 21 February 2025 as "Microsoft Power Pages Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 14 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24989 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-23652Microsoft power pages command injection vulnerabilityImproper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…EPSS 0.58%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2025-24989), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.