QID 379278
Date Published: 2024-01-24
QID 379278: Microsoft PowerShell Security Update for January 2024
PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework..
CVE-2024-0057: Microsoft PowerShell is vulnerable to Privilege Escalation.
Affected Versions:
PowerShell Version v7.2 prior to 7.2.18
PowerShell Version v7.3 prior to 7.3.11
PowerShell Version v7.4 prior to 7.4.1
QID Detection Logic: (Authenticated)
Operating System: (Windows): The QID checks for vulnerable version of file pwsh.exe.
Operating System: (Linux,MacOS X): The QID checks for vulnerable version using the command pwsh --version.
Vulnerable versions of Microsoft PowerShell are prone to Security Feature Bypass vulnerability.
Solution
Microsoft has provided the fix for this vulnerability. Please refer to CVE-2024-0057 for further information.
Vendor References
- CVE-2024-0057 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0057
CVEs related to QID 379278
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-0057 |
|