icon

Digital safety starts here for both commercial and personal Use...

Defend Your Business Against the Latest WNY Cyber Threats We offer Safe, Secure and Affordable Solutions for your Business and Personal Networks and Devices.



WNYCyber is there to help you to choose the best service providers in Western New York... We DO NOT provide the services ourselves, as we are Internet Programmers who have to deak daily with Cyber Threats... (Ugghhh)... So we know what it's like and what it takes to protect OUR and OUR CUSTOMERS DATA... We built this Website to help steer you to those that can give you the best service at realistic and non-inflated prices. We do charge or collect any fees.

Microsoft Patches Exploited Power Pages Vulnerability

Summary:
Microsoft recently addressed an elevation-of-privilege vulnerability in its Power Pages platform, which the vendor confirms was exploited as a zero-day in attacks in the wild. Power Pages is a low-code, Software-as-a-Service (SaaS) platform that allows organizations to build, host, and manage business websites with ease. The vulnerability in question, tracked as CVE-2025-24989, stems from improper access controls in Power Pages' user registration system. Specifically, the flaw allows unauthorized actors to elevate privileges over a network, potentially bypassing the user registration control.

Security Officer Comments:
Although Microsoft has not disclosed specific details regarding the exploitation attempts, this vulnerability could enable attackers to gain unauthorized access, potentially leading to the compromise of business-critical data from websites built/hosted using Power Pages. It could also enable actors the ability to inject malicious code into victims’ sites, in turn infecting end users. Overall, this vulnerability poses a significant security risk for organizations relying on Power Pages for web hosting and business operations, as it could lead to a breach of sensitive customer information, financial data, or internal communications.

Suggested Corrections:
Microsoft has emphasized that only notified organizations need to take action, as mitigations have been automatically applied to vulnerable instances. However, organizations should still conduct comprehensive access control reviews to verify that unauthorized users have not gained elevated privileges within the platform. Additionally, regular monitoring and auditing of user activity, along with the implementation of extra security measures like multi-factor authentication, will help strengthen defenses against potential attacks.

Link(s):
https://www.securityweek.com/microsoft-patches-exploited-power-pages-vulnerability/