Msrc Powershell Core 6.2 vulnerabilities

13 known vulnerabilities affecting msrc/powershell_core_6.2.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2019-1301HIGHCVSS 7.52019-09-10
CVE-2019-1301 [HIGH] .NET Core Denial of Service Vulnerability .NET Core Denial of Service Vulnerability Description: A denial of service vulnerability exists when .NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted
msrc
CVE-2019-1167HIGHCVSS 4.12019-07-09
CVE-2019-1167 [MEDIUM] Windows Defender Application Control Security Feature Bypass Vulnerability Windows Defender Application Control Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could circumvent PowerShell Core Constrained Language Mode on the machine. To exploit the vulnerability
msrc
CVE-2019-0820HIGHCVSS 7.52019-05-14
CVE-2019-0820 [HIGH] .NET Framework and .NET Core Denial of Service Vulnerability .NET Framework and .NET Core Denial of Service Vulnerability Description: A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET F
msrc
CVE-2019-0981HIGHCVSS 7.52019-05-14
CVE-2019-0981 [HIGH] .Net Framework and .Net Core Denial of Service Vulnerability .Net Framework and .Net Core Denial of Service Vulnerability Description: A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticate
msrc
CVE-2019-0980HIGHCVSS 7.52019-05-14
CVE-2019-0980 [HIGH] .Net Framework and .Net Core Denial of Service Vulnerability .Net Framework and .Net Core Denial of Service Vulnerability Description: A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticate
msrc
CVE-2019-0733MEDIUMCVSS 5.32019-05-14
CVE-2019-0733 [MEDIUM] Windows Defender Application Control Security Feature Bypass Vulnerability Windows Defender Application Control Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could circumvent Windows PowerShell Constrained Language Mode on the machine. To exploit the vulnerabil
msrc
CVE-2019-0657HIGHCVSS 5.92019-02-12
CVE-2019-0657 [MEDIUM] .NET Framework and Visual Studio Spoofing Vulnerability .NET Framework and Visual Studio Spoofing Vulnerability Description: A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's. An attacker who successfully exploited this vulnerability could use it to bypass security logic intended to ensure that a user-provided URL belonged to a specific hostname or a subdomain of that hostname. This could be used to cause privileged commu
msrc
CVE-2019-0632MEDIUMCVSS 5.32019-02-12
CVE-2019-0632 [HIGH] Windows Security Feature Bypass Vulnerability Windows Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The upd
msrc
CVE-2019-0631MEDIUMCVSS 5.32019-02-12
CVE-2019-0631 [HIGH] Windows Security Feature Bypass Vulnerability Windows Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The upd
msrc
CVE-2019-0627MEDIUMCVSS 5.32019-02-12
CVE-2019-0627 [HIGH] Windows Security Feature Bypass Vulnerability Windows Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The upd
msrc
CVE-2019-0545HIGHCVSS 7.52019-01-08
CVE-2019-0545 [HIGH] .NET Framework Information Disclosure Vulnerability .NET Framework Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations. An attacker who successfully exploited the vulnerability could retrieve content, that is normally restricted, from a web application. The security update addresses the vulnerability by enforcing CORS config
msrc
CVE-2019-0564HIGHCVSS 7.52019-01-08
CVE-2019-0564 [HIGH] ASP.NET Core Denial of Service Vulnerability ASP.NET Core Denial of Service Vulnerability Description: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing speci
msrc
CVE-2018-8416MEDIUMCVSS 6.52018-11-13
CVE-2018-8416 [MEDIUM] .NET Core Tampering Vulnerability .NET Core Tampering Vulnerability Description: A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a spe
msrc