Article Details

Scrape Timestamp (UTC): 2025-02-20 04:35:57.823

Source: https://thehackernews.com/2025/02/microsoft-patches-actively-exploited.html

Original Article Text

Click to Toggle View

Microsoft Patches Actively Exploited CVE-2025-21355 RCE Vulnerability in Bing. Microsoft has released security updates to address two Critical-rated flaws impacting Bing and Power Pages, including one that has come under active exploitation in the wild. The vulnerabilities are listed below - "Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network," the tech giant said in an advisory for CVE-2025-21355. No customer action is required. On the other hand, CVE-2025-24989 concerns a case of improper access control in Power Pages, a low-code platform for creating, hosting, and managing secure business websites, that an unauthorized attacker could exploit to elevate privileges over a network and bypass user registration control. Microsoft, which credited its own employee Raj Kumar for flagging the vulnerability, has tagged it with an "Exploitation Detected" assessment, indicating that it's aware of at least one instance of the bug being weaponized in the wild. That said, the advisory does not offer any details on the nature or scale of the attacks, the identity of the threat actors behind them, and who may have been targeted in such a manner. "This vulnerability has already been mitigated in the service and all affected customers have been notified," it added. "This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you." The Hacker News has reached out to Microsoft for further comment, and we will update the story if we get a response.

Daily Brief Summary

CYBERCRIME // Microsoft Fixes Exploited Vulnerabilities in Bing and Power Pages

Microsoft issued security updates for two critical vulnerabilities in Bing and Power Pages.

CVE-2025-21355, a remote code execution flaw in Bing, was actively exploited.

CVE-2025-24989 allowed unauthorized privilege elevation in Power Pages by exploiting registration control bypass.

Microsoft's employee, Raj Kumar, identified and reported the CVE-2025-24989 flaw.

Both vulnerabilities were addressed by Microsoft without requiring customer action, notifying only affected parties.

Users not notified by Microsoft are not affected by CVE-2025-24989.

Microsoft has already implemented service mitigations and provided remediation guidance to impacted customers.

The specifics of the attack vectors, threat actors, or victims have not been disclosed.