By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Microsoft fixes Power Pages zero-day bug exploited in attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Microsoft fixes Power Pages zero-day bug exploited in attacks
Tech News

Microsoft fixes Power Pages zero-day bug exploited in attacks

By admin 3 Min Read
Share
SHARE

Microsoft has issued a security bulletin for a high-severity elevation of privilege vulnerability in Power Pages, which hackers exploited as a zero-day in attacks.

The flaw, tracked as CVE-2025-24989, is an improper access control problem impacting Power Pages, allowing unauthorized actors to elevate their privileges over a network and bypass user registration controls.

Microsoft says it has addressed the risk at the service level and notified impacted customers accordingly, enclosing instructions on how to detect potential compromise.

“This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass,” reads Microsoft’s security bulletin.

“Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you’ve not been notified this vulnerability does not affect you.”

Microsoft Power Pages is a low-code, SaaS-based web development platform that allows users to create, host, and manage secure external-facing business websites.

It is part of the Microsoft Power Platform, which includes tools like Power BI, Power Apps, and Power Automate.

Since Power Pages is a cloud-based service, it can be assumed that exploitation occurred remotely.

The software giant has not provided details about how the flaw was exploited in attacks.

In addition to the Power Pages flaw, Microsoft also fixed a Bing remote code execution vulnerability yesterday, which is tracked as CVE-2025-21355 but has not been marked as exploited.

Problem fixed, but checks required

Microsoft has already applied fixes to the Power Pages service, and the vendor has privately shared guidance directly with impacted clients. Still, there are some generic security advice users may consider.

Admins should review activity logs for suspicious actions, user registrations, or unauthorized changes.

Since CVE-2025-24989 is an elevation of privilege bug, user lists should also be scrutinized to verify administrators and high-privileged users.

Recent changes in privileges, security roles, permissions, and web page access controls should be examined further.

Rogue accounts or those showing unauthorized activity should be immediately revoked, affected credentials should be reset, and multi-factor authentication (MFA) should be enforced across all accounts.

If you weren’t notified by Microsoft, your system was likely not affected.

You Might Also Like

Coway Airmega 50 Review: Effective and Affordable (2025)

Unlocking AI’s value securely: Navigating Key Security Imperatives

Apple’s Early 2026 Event: 8 New Products That Will Shape 2026

Critical NVIDIA Container Toolkit Flaw Allows Privilege Escalation on AI Cloud Services

South Korea now officially first Asian associate of Horizon Europe

TAGGED: Access Control, Actively Exploited, Cloud, Elevation of Privileges, Microsoft, Power Pages, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Hurricanes Legend: Cam Ward Has A Key Trait You Want To See In NFL Quarterbacks
Next Article DOGE Put Him in the Treasury Department. His Company Has Federal Contracts Worth Millions
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Crypto sector breaches $4 trillion in market value during pivotal week
Business
Charles Hoskinson says audit report ‘shaping up’ for August release
Crypto
Map: Tracking Typhoon Wipha
World News
Bitcoin Growth Rate Indicator Signals Bullish Continuation – Analyst
Crypto
Is there value in Baltic Classifieds — a soaring growth stock that brokers are buying?
Business
A one-time ’40 under 40′ rising star in fashion pleads not guilty to charges she allegedly cheated investors out of $300 million
Business
GENIUS Act blocks Big Tech, banks from dominating stablecoins: Circle exec
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Crypto sector breaches $4 trillion in market value during pivotal week

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Crypto sector breaches $4 trillion in market value during pivotal week
July 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?