PowerShellGet V2是个人开发者的一个Powershell的包管理工具。该软件用于查找、安装、更新powershell产品。 PowerShellGet V2 模块存在安全漏洞,该漏洞源于存在安全功能绕过漏洞。攻击者可利用该漏洞可能会绕过 WDAC(Windows Defender 应用程序控制)策略并在策略锁定的机器上执行任意代码。以下产品及版本受到影响: PowerShellGet 2.2.5版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | PowerShellGet 2.2.5 | 1.0.0 ~ publication |
cpe:2.3:a:microsoft:powershellget:2.2.5:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-1080 | 8.8 HIGH | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2020-16898 | 8.8 HIGH | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2020-16911 | 8.8 HIGH | GDI+ Remote Code Execution Vulnerability |
| CVE-2020-16891 | 8.8 HIGH | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2020-16946 | 8.7 HIGH | Microsoft Office SharePoint XSS Vulnerability |
| CVE-2020-16945 | 8.7 HIGH | Microsoft Office SharePoint XSS Vulnerability |
| CVE-2020-16944 | 8.7 HIGH | Microsoft SharePoint Reflective XSS Vulnerability |
| CVE-2020-16952 | 8.6 HIGH | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2020-16951 | 8.6 HIGH | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2020-16935 | 7.8 HIGH | Windows COM Server Elevation of Privilege Vulnerability |
| CVE-2020-16939 | 7.8 HIGH | Group Policy Elevation of Privilege Vulnerability |
| CVE-2020-16940 | 7.8 HIGH | Windows - User Profile Service Elevation of Privilege Vulnerability |
| CVE-2020-16967 | 7.8 HIGH | Windows Camera Codec Pack Remote Code Execution Vulnerability |
| CVE-2020-16936 | 7.8 HIGH | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2020-16930 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2020-16929 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2020-16928 | 7.8 HIGH | Microsoft Office Click-to-Run Elevation of Privilege Vulnerability |
| CVE-2020-16924 | 7.8 HIGH | Jet Database Engine Remote Code Execution Vulnerability |
| CVE-2020-16931 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2020-16954 | 7.8 HIGH | Microsoft Office Remote Code Execution Vulnerability |
Showing top 20 of 89 CVEs. View all on vendor page → →
No comments yet