QID 379110
Date Published: 2023-12-11
QID 379110: Microsoft PowerShell Multiple Vulnerabilities for November 2023
PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..
CVE-2023-36049: Microsoft PowerShell is vulnerable to Privilege Escalation.
CVE-2023-36013: Microsoft PowerShell is vulnerable to Information disclosure.
Affected Versions:
PowerShell Version v7.2 prior to 7.2.17
PowerShell Version v7.3 prior to 7.3.10
QID Detection Logic: (Authenticated)
Operating System: (Windows): The QID checks for vulnerable version of file pwsh.exe.
Operating System: (Linux,MacOS X): The QID checks for vulnerable version using the command pwsh --version.
Successful exploitation of this vulnerability could lead to disclosure of sensitive information and escalation of privileges, which may lead to further attacks.
- CVE-2023-36013 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36013 - CVE-2023-36049 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36049
CVEs related to QID 379110
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-36013 |
|
||
| CVE-2023-36049 |
|