Microsoft Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Microsoft Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and remote code execution on the targeted system.

 

Note:

These vulnerabilities affect Microsoft cloud services, and Microsoft has already implemented the necessary security mitigations.

 

Proof-of-concept code is publicly available for CVE-2025-21355. This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

 

Exploit in the wild has been detected for CVE-2025-24989. An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cusomters have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you’ve not been notified this vulnerability does not affect you.

RISK: High Risk

TYPE: Operating Systems – Windows OS

TYPE: Windows OS

Impact

  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

For CVE-2025-24989

  • Microsoft Power Pages

For CVE-2025-21355

  • Microsoft Bing


Solutions

Please visit the software vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.