Powershell Microsoft Powershell

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Powershell.

Recent Microsoft Powershell Security Advisories

Advisory Title Published
CVE-2025-54100 CVE-2025-54100 PowerShell Remote Code Execution Vulnerability December 9, 2025
CVE-2025-25004 CVE-2025-25004 PowerShell Elevation of Privilege Vulnerability October 14, 2025
CVE-2025-49734 CVE-2025-49734 PowerShell Direct Elevation of Privilege Vulnerability September 9, 2025
CVE-2024-38046 CVE-2024-38046 PowerShell Elevation of Privilege Vulnerability September 10, 2024
CVE-2024-38033 CVE-2024-38033 PowerShell Elevation of Privilege Vulnerability July 9, 2024
CVE-2024-38047 CVE-2024-38047 PowerShell Elevation of Privilege Vulnerability July 9, 2024
CVE-2024-38043 CVE-2024-38043 PowerShell Elevation of Privilege Vulnerability July 9, 2024
CVE-2023-36013 PowerShell Information Disclosure Vulnerability November 17, 2023
CVE-2022-41076 PowerShell Remote Code Execution Vulnerability December 13, 2022
CVE-2022-26788 PowerShell Elevation of Privilege Vulnerability April 12, 2022

By the Year

In 2026 there have been 0 vulnerabilities in Microsoft Powershell. Last year, in 2025 Powershell had 4 security vulnerabilities published. Right now, Powershell is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 4 7.33
2024 12 7.65
2023 9 6.89
2022 6 7.30
2021 2 5.60
2020 3 6.00
2019 0 0.00
2018 1 0.00

It may take a day or so for new Powershell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Powershell Security Vulnerabilities

Oct 2025: PowerShell Elevation of Privilege Vulnerability
CVE-2025-25004 7.3 - High - October 14, 2025

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Authorization

Sep 2025: PowerShell Direct Elevation of Privilege Vulnerability
CVE-2025-49734 7 - High - September 09, 2025

Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

Improper Restriction of Communication Channel to Intended Endpoints

Jun 2025: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2025-30399 7.5 - High - June 13, 2025

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

Untrusted Path

Jan 2025: .NET Remote Code Execution Vulnerability
CVE-2025-21171 7.5 - High - January 14, 2025

.NET Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft PowerShell OOB Write LPE CVE-2024-20098
CVE-2024-20098 - October 07, 2024

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.

Memory Corruption

PowerShell EOP Vulnerability (CVE-2024-38046)
CVE-2024-38046 7.8 - High - September 10, 2024

PowerShell Elevation of Privilege Vulnerability

Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-38095 7.5 - High - July 09, 2024

.NET and Visual Studio Denial of Service Vulnerability

Improper Input Validation

Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-30105 7.5 - High - July 09, 2024

.NET and Visual Studio Denial of Service Vulnerability

Resource Exhaustion

Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38033 7.3 - High - July 09, 2024

PowerShell Elevation of Privilege Vulnerability

Improper Input Validation

Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38043 7.8 - High - July 09, 2024

PowerShell Elevation of Privilege Vulnerability

Improper Input Validation

Jul 2024: PowerShell Elevation of Privilege Vulnerability
CVE-2024-38047 7.8 - High - July 09, 2024

PowerShell Elevation of Privilege Vulnerability

Improper Input Validation

Microsoft .NET & VS Remote Code Execution via RCE Vulnerability
CVE-2024-30045 6.3 - Medium - May 14, 2024

.NET and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework & Visual Studio RCE via CVE-2024-21409
CVE-2024-21409 7.3 - High - April 09, 2024

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

.NET / Visual Studio DoS Vulnerability (CVE-2024-21392)
CVE-2024-21392 7.5 - High - March 12, 2024

.NET and Visual Studio Denial of Service Vulnerability

Microsoft QUIC DoS via malformed QUIC packets
CVE-2024-26190 7.5 - High - March 12, 2024

Microsoft QUIC Denial of Service Vulnerability

Microsoft .NET Framework Security Bypass CVE-2024-0057
CVE-2024-0057 9.8 - Critical - January 09, 2024

NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

OpenSSH <9.6 BPP handshake flaw allows integrity bypass (Terrapin attack)
CVE-2023-48795 5.9 - Medium - December 18, 2023

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

Improper Validation of Integrity Check Value

Nov 2023: PowerShell Information Disclosure Vulnerability
CVE-2023-36013 6.5 - Medium - November 20, 2023

PowerShell Information Disclosure Vulnerability

Use of Hard-coded Credentials

Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36792 7.8 - High - September 12, 2023

Visual Studio Remote Code Execution Vulnerability

Integer Overflow or Wraparound

Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36793 7.8 - High - September 12, 2023

Visual Studio Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36794 7.8 - High - September 12, 2023

Visual Studio Remote Code Execution Vulnerability

Integer underflow

Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36796 7.8 - High - September 12, 2023

Visual Studio Remote Code Execution Vulnerability

Integer underflow

Sep 2023: .NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-36799 6.5 - Medium - September 12, 2023

.NET Core and Visual Studio Denial of Service Vulnerability

Resource Exhaustion

PowerShell OOB Read Local Info Disclosure (CVE-2023-20688)
CVE-2023-20688 4.4 - Medium - April 06, 2023

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441821; Issue ID: ALPS07441821.

Out-of-bounds Read

MS .NET Framework DoS Vulnerability (CVE-2023-21538)
CVE-2023-21538 7.5 - High - January 10, 2023

.NET Denial of Service Vulnerability

WinGfx EoP Vulnerability
CVE-2022-41121 7.8 - High - December 13, 2022

Windows Graphics Component Elevation of Privilege Vulnerability

Microsoft PowerShell RCE Vulnerability CVE-2022-41076
CVE-2022-41076 8.5 - High - December 13, 2022

PowerShell Remote Code Execution Vulnerability

.NET Spoofing Vulnerability in .NET Framework
CVE-2022-34716 5.9 - Medium - August 09, 2022

.NET Spoofing Vulnerability

.NET and Visual Studio Denial of Service Vulnerability
CVE-2022-23267 7.5 - High - May 10, 2022

.NET and Visual Studio Denial of Service Vulnerability

PowerShell Elevation of Privilege Vulnerability
CVE-2022-26788 7.8 - High - April 15, 2022

PowerShell Elevation of Privilege Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2022-24512 6.3 - Medium - March 09, 2022

.NET and Visual Studio Remote Code Execution Vulnerability

Microsoft PowerShell Spoofing Vulnerability
CVE-2021-43896 5.5 - Medium - December 15, 2021

Microsoft PowerShell Spoofing Vulnerability

.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-41355 5.7 - Medium - October 13, 2021

.NET Core and Visual Studio Information Disclosure Vulnerability

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash
CVE-2020-8927 5.3 - Medium - September 15, 2020

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

length manipulation

<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could
CVE-2020-0951 6.7 - Medium - September 11, 2020

<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code.</p> <p>The update addresses the vulnerability by correcting how PowerShell commands are validated when WDAC protection is enabled.</p>

May 2020:
CVE-2020-1108 - May 21, 2020

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

Jul 2018:
CVE-2018-8327 - July 11, 2018

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Powershell or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe