Microsoft Updates Actively Utilized Power Pages Authorization Escalation Weakness
Microsoft has issued security patches to fix two Critical-rated vulnerabilities affecting Bing and Power Pages, comprising one currently being actively exploited. The vulnerabilities are provided below –
CVE-2025-21355 (CVSS score: 8.6) – Microsoft Bing Remote Code Execution Vulnerability
CVE-2025-24989 (CVSS score: 8.2) – Microsoft Power Pages Elevation of Privilege Vulnerability
“
