QID 378410

Date Published: 2023-04-14

QID 378410: Microsoft PowerShell Remote Code Execution (RCE) Vulnerability

PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..

PowerShell is vulnerable to Remote Code Execution Vulnerability

Affected Versions:
PowerShell Version 7.2 Prior to 7.2.11
PowerShell Version 7.3 Prior to 7.3.4

QID Detection Logic: (Authenticated)
Operating System: Windows
The QID checks for vulnerable version of file pwsh.exe.

Successful exploitation could lead to remote code execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to install the latest version of PowerShell which can be in the for more details

    CVEs related to QID 378410

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-28260 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28260