Microsoft Powershell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Powershell.
Recent Microsoft Powershell Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2025-54100 | CVE-2025-54100 PowerShell Remote Code Execution Vulnerability | December 9, 2025 |
| CVE-2025-25004 | CVE-2025-25004 PowerShell Elevation of Privilege Vulnerability | October 14, 2025 |
| CVE-2025-49734 | CVE-2025-49734 PowerShell Direct Elevation of Privilege Vulnerability | September 9, 2025 |
| CVE-2024-38046 | CVE-2024-38046 PowerShell Elevation of Privilege Vulnerability | September 10, 2024 |
| CVE-2024-38033 | CVE-2024-38033 PowerShell Elevation of Privilege Vulnerability | July 9, 2024 |
| CVE-2024-38047 | CVE-2024-38047 PowerShell Elevation of Privilege Vulnerability | July 9, 2024 |
| CVE-2024-38043 | CVE-2024-38043 PowerShell Elevation of Privilege Vulnerability | July 9, 2024 |
| CVE-2023-36013 | PowerShell Information Disclosure Vulnerability | November 17, 2023 |
| CVE-2022-41076 | PowerShell Remote Code Execution Vulnerability | December 13, 2022 |
| CVE-2022-26788 | PowerShell Elevation of Privilege Vulnerability | April 12, 2022 |
By the Year
In 2026 there have been 0 vulnerabilities in Microsoft Powershell. Last year, in 2025 Powershell had 4 security vulnerabilities published. Right now, Powershell is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 4 | 7.33 |
| 2024 | 12 | 7.65 |
| 2023 | 9 | 6.89 |
| 2022 | 6 | 7.30 |
| 2021 | 2 | 5.60 |
| 2020 | 3 | 6.00 |
| 2019 | 0 | 0.00 |
| 2018 | 1 | 0.00 |
It may take a day or so for new Powershell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Powershell Security Vulnerabilities
Oct 2025: PowerShell Elevation of Privilege Vulnerability
CVE-2025-25004
7.3 - High
- October 14, 2025
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Authorization
Sep 2025: PowerShell Direct Elevation of Privilege Vulnerability
CVE-2025-49734
7 - High
- September 09, 2025
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
Improper Restriction of Communication Channel to Intended Endpoints
Jun 2025: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2025-30399
7.5 - High
- June 13, 2025
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
Untrusted Path
Jan 2025: .NET Remote Code Execution Vulnerability
CVE-2025-21171
7.5 - High
- January 14, 2025
.NET Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft PowerShell OOB Write LPE CVE-2024-20098
CVE-2024-20098
- October 07, 2024
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.
Memory Corruption
PowerShell EOP Vulnerability (CVE-2024-38046)
CVE-2024-38046
7.8 - High
- September 10, 2024
PowerShell Elevation of Privilege Vulnerability
Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-38095
7.5 - High
- July 09, 2024
.NET and Visual Studio Denial of Service Vulnerability
Improper Input Validation
Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-30105
7.5 - High
- July 09, 2024
.NET and Visual Studio Denial of Service Vulnerability
Resource Exhaustion
Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38033
7.3 - High
- July 09, 2024
PowerShell Elevation of Privilege Vulnerability
Improper Input Validation
Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38043
7.8 - High
- July 09, 2024
PowerShell Elevation of Privilege Vulnerability
Improper Input Validation
Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38047
7.8 - High
- July 09, 2024
PowerShell Elevation of Privilege Vulnerability
Improper Input Validation
Microsoft .NET & VS Remote Code Execution via RCE Vulnerability
CVE-2024-30045
6.3 - Medium
- May 14, 2024
.NET and Visual Studio Remote Code Execution Vulnerability
Microsoft .NET Framework & Visual Studio RCE via CVE-2024-21409
CVE-2024-21409
7.3 - High
- April 09, 2024
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET / Visual Studio DoS Vulnerability (CVE-2024-21392)
CVE-2024-21392
7.5 - High
- March 12, 2024
.NET and Visual Studio Denial of Service Vulnerability
Microsoft QUIC DoS via malformed QUIC packets
CVE-2024-26190
7.5 - High
- March 12, 2024
Microsoft QUIC Denial of Service Vulnerability
Microsoft .NET Framework Security Bypass CVE-2024-0057
CVE-2024-0057
9.8 - Critical
- January 09, 2024
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
OpenSSH <9.6 BPP handshake flaw allows integrity bypass (Terrapin attack)
CVE-2023-48795
5.9 - Medium
- December 18, 2023
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
Improper Validation of Integrity Check Value
Nov 2023: PowerShell Information Disclosure Vulnerability
CVE-2023-36013
6.5 - Medium
- November 20, 2023
PowerShell Information Disclosure Vulnerability
Use of Hard-coded Credentials
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36792
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer Overflow or Wraparound
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36793
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36794
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer underflow
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36796
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer underflow
Sep 2023: .NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-36799
6.5 - Medium
- September 12, 2023
.NET Core and Visual Studio Denial of Service Vulnerability
Resource Exhaustion
PowerShell OOB Read Local Info Disclosure (CVE-2023-20688)
CVE-2023-20688
4.4 - Medium
- April 06, 2023
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441821; Issue ID: ALPS07441821.
Out-of-bounds Read
MS .NET Framework DoS Vulnerability (CVE-2023-21538)
CVE-2023-21538
7.5 - High
- January 10, 2023
.NET Denial of Service Vulnerability
WinGfx EoP Vulnerability
CVE-2022-41121
7.8 - High
- December 13, 2022
Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft PowerShell RCE Vulnerability CVE-2022-41076
CVE-2022-41076
8.5 - High
- December 13, 2022
PowerShell Remote Code Execution Vulnerability
.NET Spoofing Vulnerability in .NET Framework
CVE-2022-34716
5.9 - Medium
- August 09, 2022
.NET Spoofing Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
CVE-2022-23267
7.5 - High
- May 10, 2022
.NET and Visual Studio Denial of Service Vulnerability
PowerShell Elevation of Privilege Vulnerability
CVE-2022-26788
7.8 - High
- April 15, 2022
PowerShell Elevation of Privilege Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2022-24512
6.3 - Medium
- March 09, 2022
.NET and Visual Studio Remote Code Execution Vulnerability
Microsoft PowerShell Spoofing Vulnerability
CVE-2021-43896
5.5 - Medium
- December 15, 2021
Microsoft PowerShell Spoofing Vulnerability
.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-41355
5.7 - Medium
- October 13, 2021
.NET Core and Visual Studio Information Disclosure Vulnerability
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash
CVE-2020-8927
5.3 - Medium
- September 15, 2020
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
length manipulation
<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could
CVE-2020-0951
6.7 - Medium
- September 11, 2020
<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code.</p> <p>The update addresses the vulnerability by correcting how PowerShell commands are validated when WDAC protection is enabled.</p>
May 2020:
CVE-2020-1108
- May 21, 2020
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Jul 2018:
CVE-2018-8327
- July 11, 2018
A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Powershell or by Microsoft? Click the Watch button to subscribe.