Executive brief
Microsoft PowerShell, a widely-used command-line automation tool in Windows environments, contains a command injection vulnerability. An authorized attacker with local access could exploit this flaw to execute arbitrary code on affected systems, potentially compromising system integrity and data security.
Technical details
The vulnerability is an improper neutralization of special elements in command processing (command injection, CWE-77/78) within Microsoft PowerShell. The flaw allows an authorized attacker with local access to execute arbitrary code by injecting specially-crafted commands. Attack requires local access and attacker authorization. No patch availability information is provided in the advisory.
Affected products
- Microsoft PowerShell
Timeline
- 2026-08-14: disclosed