Executive brief
Windows PowerShell contains a path traversal vulnerability that allows an attacker to bypass a security feature over the network. An unauthorized user could exploit this flaw to access or manipulate files outside the intended restricted directory, potentially leading to unauthorized data access or system compromise.
Technical details
This vulnerability is a path traversal flaw (CWE-22) in Windows PowerShell that allows improper limitation of pathname access to a restricted directory. The vulnerability can be exploited over a network by an unauthorized attacker to bypass a security feature. The specific vulnerable component, preconditions (such as authentication requirements), and exact attack vector are not detailed in the available summary, but the network-reachable nature suggests the attack can be performed without requiring physical access or local system access.
Affected products
- Microsoft Windows PowerShell
Timeline
- 2026-09-08: disclosed