LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24989: Microsoft Power Pages Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 21, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 14, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24989 to its Known Exploited Vulnerabilities catalog on Feb 21, 2025, with a federal patch deadline of Mar 14, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

CVE-2025-24989 is an improper access control vulnerability in Microsoft Power Pages. It allows an unauthorized attacker to elevate privileges over a network, potentially bypassing the user registration control. This matters because Power Pages often hosts public-facing or semi-public business portals; successful abuse can grant elevated access without proper registration or authorization checks, increasing risk of unauthorized data access or further compromise of the environment.

Defenders should treat this as a cloud-service access-control issue and confirm all product-specific details against the Microsoft advisory. CISA notes the required action is to apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-284 (Improper Access Control). In this class of flaw, the application fails to enforce correct authorization boundaries on sensitive operations. According to the CISA summary, an unauthorized attacker can elevate privileges over a network and potentially bypass the user registration control in Microsoft Power Pages.

At a high level, an attacker who can reach the affected Power Pages surface may interact with registration or access-control logic in a way that grants higher privileges than intended. Exact request patterns, endpoints, or conditions are not provided here; treat any public technical write-ups as unconfirmed until validated against the vendor advisory. The impact is privilege elevation rather than remote code execution, but elevated access on a portal can still expose data or administrative functions.

Am I affected? How to find it in your systems

Microsoft Power Pages is a low-code platform commonly used to build external-facing websites and portals that integrate with Microsoft Dataverse and other Microsoft cloud services. It typically runs as a cloud-hosted service rather than on-premises software.

If you lack centralized inventory, query the Power Platform admin center or use available Microsoft Graph / Power Platform APIs to enumerate sites. Engage application owners who manage customer or partner portals.

How to remediate

Patching or applying the vendor-supplied mitigation is the primary action. Follow Microsoft’s instructions for this CVE exactly; the CISA required action is to apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor mitigation can be applied, reduce exposure with compensating controls appropriate to a cloud portal service.

If your data may have been exposed

Actively exploited access-control vulnerabilities can lead to unauthorized access and subsequent data exposure or account takeover. Although ransomware use is not documented for this CVE, any privilege elevation on a business portal warrants investigation of portal logs, Dataverse records, and related identity activity for signs of abuse.

If you believe accounts or data may have been accessed, follow your incident-response process: contain affected portals, reset credentials of potentially elevated accounts, and review data-access logs. Separately, individuals can run a free exposure scan of their email addresses against known breach data sets to check whether their credentials appear in prior public breaches, which can help prioritize password resets and monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Power Pages
WeaknessCWE-284
Added to CISA KEVFeb 21, 2025
Federal patch deadlineMar 14, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities