Microsoft Powershell vulnerabilities
18 known vulnerabilities affecting microsoft/powershell.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH11MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2018-8327P2CRITICALCVSS 9.8fixed in 1.7.02018-07-11
CVE-2018-8327 [CRITICAL] CVE-2018-8327: A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor S
A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.
nvd
CVE-2020-0605P3HIGHCVSS 8.8≥ 0, < 7.0.02024-02-02
CVE-2020-0605 [HIGH] PowerShell is subject to remote code execution vulnerability
PowerShell is subject to remote code execution vulnerability
# Microsoft Security Advisory CVE-2020-0605: .NET Framework Remote Code Execution Vulnerability
## Executive Summary
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.
An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current
ghsaosv
CVE-2024-0057P3CRITICALCVSS 9.8≥ 7.2, < 7.2.18≥ 7.3, < 7.3.11+1 more2024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2026-26171P3HIGHCVSS 7.5≥ 7.5, < 7.5.6≥ 7.6, < 7.6.12026-04-14
CVE-2026-26171 [HIGH] CWE-400 CVE-2026-26171: Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-30399P3HIGHCVSS 7.5≥ 7.4, < 7.4.11≥ 7.5, < 7.5.22025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-26143P3HIGHCVSS 7.8≥ 7.4, < 7.4.14≥ 7.5, < 7.5.52026-04-14
CVE-2026-26143 [HIGH] CWE-20 CVE-2026-26143: Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a securi
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2020-1108P3HIGHCVSS 7.5v7.02020-05-21
CVE-2020-1108 [HIGH] CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web req
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
nvd
CVE-2020-0951P3MEDIUMCVSS 6.7≥ 7.0, < 7.0.8≥ 7.1, < 7.1.5+1 more2020-09-11
CVE-2020-0951 [MEDIUM] CVE-2020-0951: <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) whi
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.
To exploit the vulnerability, an attacker need administrator access on a local machine
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 7.2, < 7.2.19≥ 7.3, < 7.3.12+1 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-25004P3HIGHCVSS 7.3≥ 7.4, < 7.4.13≥ 7.5, < 7.5.42025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 7.0, < 7.0.9≥ 7.1, < 7.1.6+1 more2020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2022-41121P3HIGHCVSS 7.8v7.2v7.32022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-23267P3HIGHCVSS 7.5≥ 7.0, < 7.0.11≥ 7.2, < 7.2.42022-05-10
CVE-2022-23267 [HIGH] CVE-2022-23267: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-21392P3HIGHCVSS 7.5≥ 7.3, < 7.3.12v7.42024-03-12
CVE-2024-21392 [HIGH] CWE-400 CVE-2024-21392: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-30045P3MEDIUMCVSS 6.3≥ 7.4, < 7.4.32024-05-14
CVE-2024-30045 [MEDIUM] CWE-122 CVE-2024-30045: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-49734P3HIGHCVSS 7.0≥ 7.4, < 7.4.12≥ 7.5, < 7.5.32025-09-09
CVE-2025-49734 [HIGH] CWE-923 CVE-2025-49734: Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24512P3MEDIUMCVSS 6.3≥ 7.0, < 7.0.9≥ 7.1, < 7.1.6+1 more2022-03-09
CVE-2022-24512 [MEDIUM] CWE-94 CVE-2022-24512: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2021-41355P4MEDIUMCVSS 5.7≥ 7.1, < 7.1.52021-10-13
CVE-2021-41355 [MEDIUM] CVE-2021-41355: .NET Core and Visual Studio Information Disclosure Vulnerability
.NET Core and Visual Studio Information Disclosure Vulnerability
nvd