The flaw, tracked as CVE-2025-23989, is an improper access control problem impacting Power Pages, allowing unauthorized actors to elevate their privileges over a network and bypass user registration controls. In addition to the Power Pages flaw, Microsoft also fixed a Bing remote code execution vulnerability yesterday, which is tracked as CVE-2025-21355 but has not been marked as exploited. Microsoft has issued a security bulletin for a high-severity elevation of privilege vulnerability in Power Pages, which hackers exploited as a zero-day in attacks. Microsoft Power Pages is a low-code, SaaS-based web development platform that allows users to create, host, and manage secure external-facing business websites. Microsoft has already applied fixes to the Power Pages service, and the vendor has privately shared guidance directly with impacted clients. Microsoft says it has addressed the risk at the service level and notified impacted customers accordingly, enclosing instructions on how to detect potential compromise. Since Power Pages is a cloud-based service, it can be assumed that exploitation occurred remotely.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 20 Feb 2025 14:35:19 +0000