Описание
Microsoft PowerShell Security Feature Bypass Vulnerability
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker would have to send the victim a malicious file that the victim would have to execute.
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
Exploiting this vulnerability bypasses dynamic-expression security checks which may lead to arbitrary code execution when then -SkipLimitCheck is used with Import-PowerShellDataFile. If you do not use the -SkipLimitCheck switch, you are not affected.
Is the Windows native version of PowerShell affected by this vulnerability?
No, this vulnerability was introduced after PowerShell was forked from Windows powerShell so the inbox version is not affected.
The current store app addresses the vulnerability.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| PowerShell 7.4 | ||
| PowerShell 7.5 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.8 High
CVSS3
Связанные уязвимости
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Уязвимость интерпретатора команд PowerShell операционной системы Windows, позволяющая нарушителю обойти существующие ограничения безопасности
EPSS
7.8 High
CVSS3