← Back to browse · API

CVE-2025-24989

Severity
HIGH
CVSS
8.2
EPSS
0.01722
Risk score
58.4
CISA KEV
Yes
PoC
No
Published
2025-02-21
Modified
2025-02-21
First seen
2026-08-07
Aliases
EUVD-2025-4642, GHSA-PXJR-976R-24R6
Products
Microsoft:Microsoft Power Pages -, Microsoft:Power Pages
Sources
cisa.gov CVE-2025-24989
euvd EUVD-2025-4642

Description

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

References