EXECUTIVE SUMMARY:
Microsoft has released security updates to fix two Critical-rated vulnerabilities in Bing and Power Pages, including one actively exploited in the wild. CVE-2025-21355 is a Microsoft Bing remote code execution flaw caused by missing authentication for a critical function, allowing unauthorized attackers to execute code over a network. CVE-2025-24989 is an elevation of privilege issue in Power Pages due to improper access control, enabling attackers to bypass user registration controls.
[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Microsoft has released security updates to fix two Critical-rated vulnerabilities in Bing and Power Pages, including one actively exploited in the wild. CVE-2025-21355 is a Microsoft Bing remote code execution flaw caused by missing authentication for a critical function, allowing unauthorized attackers to execute code over a network. CVE-2025-24989 is an elevation of privilege issue in Power Pages due to improper access control, enabling attackers to bypass user registration controls.
[emaillocker id="1283"]
Microsoft has patched two critical vulnerabilities in Bing and Power Pages, including one under active exploitation. Affected customers have been notified, and mitigations are already in place.
RECOMMENDATION:
For CVE-2025-21355, We strongly recommend you update Microsoft product to below link
For CVE-2025-24989, We strongly recommend you update Microsoft product to below link
Download from here: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24989
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2025/02/microsoft-patches-actively-exploited.html