Microsoft Power Pages Improper Access Control Vulnerability
Microsoft · Power Pages
Date added (CISA)
2025-02-21
Remediation due
2025-03-14
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.