QID 379048

Date Published: 2023-11-21

QID 379048: Microsoft PowerShell Remote Code Execution Vulnerability for September 2023

PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..

CVE-2023-36796,CVE-2023-36792,CVE-2023-36793,CVE-2023-36794: Microsoft PowerShell is vulnerable to Remote Code Execution.

Affected Versions:
PowerShell Version v7.2 Prior to v7.2.12

QID Detection Logic: (Authenticated)
Operating System: Windows: The QID checks for vulnerable version of file pwsh.exe.

Successful exploitation of this vulnerability could lead to arbitrary code execution which lead to other attacks.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Microsoft has provided the fix for this vulnerability. Please refer to CVE-2023-36792,CVE-2023-36796,CVE-2023-36793,CVE-2023-36794 for further information.

    CVEs related to QID 379048

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-36792 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36792
    CVE-2023-36793 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36793
    CVE-2023-36794 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36794
    CVE-2023-36796 URL Logo msrc.microsoft.com/update-guide/en-us/advisory/CVE-2023-36796