CVE-2025-24989 is a critical improper access control vulnerability in Microsoft Power Pages, allowing unauthorized attackers to elevate privileges over a network by bypassing user registration controls. With a CVSS score of 9.8, it poses a severe risk, enabling full compromise of confidentiality, integrity, and availability without user interaction. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage. Microsoft has already mitigated this issue in the service, notified affected customers, and provided remediation guidance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:power_pages:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.