Threat Advisory

Microsoft Patches Critical Bing and Power Pages Vulnerabilities

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:
Microsoft has released security updates to fix two Critical-rated vulnerabilities in Bing and Power Pages, including one actively exploited in the wild. CVE-2025-21355 is a Microsoft Bing remote code execution flaw caused by missing authentication for a critical function, allowing unauthorized attackers to execute code over a network. CVE-2025-24989 is an elevation of privilege issue in Power Pages due to improper access control, enabling attackers to bypass user registration controls.

 [/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:
Microsoft has released security updates to fix two Critical-rated vulnerabilities in Bing and Power Pages, including one actively exploited in the wild. CVE-2025-21355 is a Microsoft Bing remote code execution flaw caused by missing authentication for a critical function, allowing unauthorized attackers to execute code over a network. CVE-2025-24989 is an elevation of privilege issue in Power Pages due to improper access control, enabling attackers to bypass user registration controls.

 [emaillocker id="1283"]

  • CVE-2025-21355: A remote code execution vulnerability in Microsoft Bing, with a CVSS score of 8.6, stems from missing authentication for a critical function, allowing an unauthorized attacker to execute arbitrary code over a network. Microsoft has stated that no customer action is required, as the issue has already been mitigated in the service.

 

  • CVE-2025-24989: An elevation of privilege vulnerability in Microsoft Power Pages, with a CVSS score of 8.2, is caused by improper access control, allowing an unauthorized attacker to bypass user registration controls over a network. Microsoft has confirmed active exploitation of this flaw and has notified affected customers, providing instructions on reviewing their sites for potential exploitation and cleanup methods.

Microsoft has patched two critical vulnerabilities in Bing and Power Pages, including one under active exploitation. Affected customers have been notified, and mitigations are already in place.

RECOMMENDATION:

For CVE-2025-21355, We strongly recommend you update Microsoft product to below link

For CVE-2025-24989, We strongly recommend you update Microsoft product to below link

Download from here: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24989

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2025/02/microsoft-patches-actively-exploited.html

[/emaillocker]
crossmenu