Microsoft PowerShell是美国Microsoft公司的一款命令行脚本与自动化工具。 Microsoft PowerShell 7.4.19.0之前版本、7.5.10.0之前版本和7.6.5之前版本存在命令注入漏洞,该漏洞源于对命令中特殊元素的中和不当(命令注入),可能导致已授权攻击者在本地执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | PowerShell 7.4 | 7.4.0< 7.4.19.0 |
affected |
| Microsoft | PowerShell 7.5 | 7.5.0< 7.5.10.0 |
affected |
| Microsoft | PowerShell 7.6 | 7.6.0< 7.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | PowerShell 7.4 | 7.4.0 ~ 7.4.19.0 | - |
|
| Microsoft | PowerShell 7.5 | 7.5.0 ~ 7.5.10.0 | - |
|
| Microsoft | PowerShell 7.6 | 7.6.0 ~ 7.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72970 | 8.3 HIGH | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-69414 | 7.8 HIGH | Microsoft Defender Elevation of Privilege Vulnerability |
No comments yet