QID 378972
Date Published: 2023-10-30
QID 378972: Microsoft PowerShell Information Disclosure Vulnerability for August 2022
PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..
CVE-2022-34716: Microsoft PowerShell is vulnerable to Information Disclosure Vulnerability
Affected Versions:
PowerShell Version 7.0 Prior to 7.0.12
PowerShell Version 7.2 Prior to 7.2.6
QID Detection Logic: (Authenticated)
Operating System:
Windows: The QID checks for vulnerable version of file pwsh.exe.
Linux: This QID checks for installed vulnerable version using "pwsh --version" command.
Successful exploitation of this vulnerability could lead to unauthorized access of privileged information.
Solution
Microsoft has provided the fix for this vulnerability. Please refer to PowerShell Security Advisory for further information.
Vendor References
- PowerShell Security Advisory -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34716
CVEs related to QID 378972
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PowerShell Security Advisory |
|