QID 378971

Date Published: 2023-10-30

QID 378971: Microsoft PowerShell Elevation of Privilege Vulnerability for April 2022

PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..

CVE-2022-26788: Microsoft PowerShell is vulnerable to elevation of privilege Vulnerability

Affected Versions:
PowerShell Version 7.0 Prior to 7.0.10
PowerShell Version 7.1 Prior to 7.1.7
PowerShell Version 7.2 Prior to 7.2.3

QID Detection Logic: (Authenticated)
Operating System: Windows: The QID checks for vulnerable version of file pwsh.exe.
Linux: This QID checks for installed vulnerable version using "pwsh --version" command.

Successful exploitation of this vulnerability may allow an low privileged user to escalate to higher privileges and perform tasks.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Microsoft has provided the fix for this vulnerability. Please refer to PowerShell Security Advisory for further information.
    Vendor References

    CVEs related to QID 378971

    Software Advisories
    Advisory ID Software Component Link
    PowerShell Security Advisory URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26788