peter bassill · operator
$ cve CVE-2025-24989 JSON

CVE-2025-24989 KEV

8.2
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 75)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-14.

Description

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.

Scoring

CVSS8.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS1.62% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-284
On CISA KEVyes — remediate by 2025-03-14
Public exploitnone known
Published2025-02-19
Last modified2026-06-17

CISA KEV

NameMicrosoft Power Pages Improper Access Control Vulnerability
Added2025-02-21
Due2025-03-14
Vendor / productMicrosoft / Power Pages
Ransomware usenone reported

Affected (1)

VendorProduct
microsoftpower pages

References

→ the Explorer  ·  watch your stack  ·  NVD