Executive brief
A vulnerability in Windows PowerShell, a core automation and configuration tool, could allow an authorized user to execute malicious code remotely across a network. If exploited, an attacker could gain full control over affected systems, potentially leading to data theft, service disruption, or further movement within the corporate network. This issue requires a user to perform a specific action, such as clicking a link or opening a file, to trigger the attack.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Windows PowerShell. The flaw allows an authenticated attacker with low privileges to execute arbitrary code over the network, provided they can induce a user to interact with a malicious element (UI:R). The root cause is improper validation of file paths, which can be bypassed to access or execute files outside of intended directories. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue.
Affected products
- Microsoft Windows PowerShell Windows 10, Windows 11, Windows Server 2012
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory