QID 376620
Date Published: 2022-05-24
QID 376620: PowerShell Denial of Service (DoS) Vulnerability
PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..
A denial of service and an information disclosure vulnerability exists in .NET 5.0, .NET 6.0 and .NET Core 3.1.
Affected Versions:
PowerShell Version 7.0 Prior to 7.0.11
PowerShell Version 7.2 Prior to 7.2.4
QID Detection Logic: (Authenticated)
Operating System: Windows and Linux
The QID checks for vulnerable version of file pwsh.exe and QID checks for vulnerable version of PowerShell Core by running command pwsh --version on linux systems.
NOTE: The Windows check will only work for msi installations.
Successful exploitation of the vulnerability may allow an attacker to perform denial of service and information disclosure vulnerability on target machine.
- CVE-2022-23267 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23267
CVEs related to QID 376620
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-23267 |
|