Vulnerability record · CVE-2025-24989 · published 19 February 2025
CVE-2025-24989: Microsoft Power Pages improper access control allows privilege elevation
Microsoft · Power Pages
Power Pages contains an improper access control flaw that lets an unauthorized network attacker elevate privileges, potentially bypassing the user registration control. Microsoft states the vulnerability has already been mitigated in the service and affected customers were notified, so this record describes a service-side fix rather than a customer-applied patch.
Description
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, plus confirmed exploitation in the CISA KEV catalog, makes this a top remediation priority despite the low EPSS score.
What it is
Power Pages contains an improper access control flaw that lets an unauthorized network attacker elevate privileges, potentially bypassing the user registration control. Microsoft states the vulnerability has already been mitigated in the service and affected customers were notified, so this record describes a service-side fix rather than a customer-applied patch.
Impact
An unauthenticated attacker can bypass registration controls and elevate privileges, gaining high confidentiality, integrity and availability impact on the affected site. This can expose or corrupt site data and allow unauthorized administrative-level actions.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the Power Pages service itself, so any exposed site using the affected registration control is a potential target.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-21, indicating known exploitation in the wild. EPSS is low at roughly 1.6% (74.9th percentile), but the KEV listing and vendor notification of affected customers outweigh that signal.
What to do
- Confirm whether Microsoft notified you as an affected customer; if not, the vendor states you are not affected.
- Apply the service-side mitigation Microsoft already deployed and follow the vendor's remediation guidance.
- Review Power Pages sites for signs of unauthorized registration or privilege changes and perform the cleanup steps Microsoft provided.
- If mitigations are unavailable, follow BOD 22-01 guidance for cloud services or discontinue use of the product.
- Track the CISA KEV due date of 2025-03-14 for federal remediation timelines.
Detection
- Audit Power Pages registration and authentication logs for accounts created outside expected registration flows.
- Review site user and role assignments for unexpected privilege grants or new administrative accounts.
- Monitor for anomalous access patterns to Power Pages sites that bypass normal registration controls.
- Compare current site configuration and user lists against known-good baselines to spot unauthorized changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24989 to the Known Exploited Vulnerabilities catalog on 21 February 2025 as "Microsoft Power Pages Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 14 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24989 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24989 | US Government Resource |
Track CVE-2025-24989 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24989), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.