QID 376161

Date Published: 2021-12-15

QID 376161: Microsoft PowerShell Spoofing Vulnerability

Microsoft has released a security Update for PowerShell which resolves Information Disclosure Vulnerability.
Note: This does not affect windows operating system. Affected versions:
Powershell versions prior to 7.2.x

QID Detection Logic: (Authenticated)
This QID detects vulnerable versions of powershell using pwsh --version

Successful exploitation of this vulnerability could lead to Disclosure of Sensitive Information.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released patch in PowerShell.
    For more information please visit here

    CVEs related to QID 376161

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-43896 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43896