Microsoft fixes Power Pages security flaw, tells users to be on their guard

The best free firewall
(Image credit: Shutterstock)

  • Microsoft recently found and patched a high-severity bug in Power Pages
  • The bug allowed malicious actors to log into target websites
  • The vulnerability was fixed, but Microsoft warns potential victims to be on guard

Microsoft has fixed a high-severity vulnerability in its Power Pages product, and has warned users to be on the lookout for signs of exploitation.

The company recently published details about CVE-2025-24989, an improper access control vulnerability in Power Pages, which allows unauthorized attackers to elevate privileges over a network, potentially bypassing the user registration control. In other words, unauthorized attackers could use the vulnerability to log into other people’s websites. It was given a severity score of 8.2/10 (high).

We don’t know who is behind the attack, or how many websites are affected. According to Microsoft, Power Pages has more than 250 million active website users on a monthly basis including Britain’s National Health Service.

Patched flaws

Microsoft Power Pages is a low-code platform for building secure, data-driven websites, enabling users to create and customize sites with drag-and-drop simplicity while integrating with other Microsoft services like Power Automate and Dataverse.

It is designed for businesses and organizations that need external-facing portals for customers, partners, or employees without requiring extensive coding expertise. It is a Software-as-a-Service (SaaS), meaning all patches and updates are done by Microsoft on its servers.

The company already deployed the patch, but that doesn’t mean the trouble is gone. Apparently, cybercriminals discovered the flaw before Microsoft did, and used it to access at least a few websites. It is impossible to know what they did with the access. They could redirect people to malicious websites, serve malvertising, steal data, and more.

The company warned some users to be careful and look for signs of exploitation.

“This vulnerability has already been mitigated in the service and all affected customers have been notified,” Microsoft said. “Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.”

Via The Register

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
A person at a laptop with a cybersecure lock symbol floating above it.
A worrying security flaw could have left Microsoft SharePoint users open to attack
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale