Microsoft
Microsoft Powershell: vulnerabilidades y CVE
Microsoft Powershell tiene 31 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19591 | Alta (8.8) | 0.30% | — | 1 sept 2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token… |
| CVE-2026-50523 | Alta (7.8) | 0.32% | — | 14 ago 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. |
| CVE-2026-70338 | Alta (7.8) | 0.36% | — | 11 ago 2026 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2026-70337 | Alta (8.8) | 0.94% | — | 11 ago 2026 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. |
| CVE-2026-59119 | Alta (7.3) | 0.38% | — | 11 ago 2026 | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. |
| CVE-2026-58612 | Alta (7.5) | 0.87% | — | 11 ago 2026 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26171 | Alta (7.5) | 2.3% | — | 14 abr 2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-26143 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2025-25004 | Alta (7.3) | 0.48% | — | 14 oct 2025 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49734 | Alta (7) | 0.33% | — | 9 sept 2025 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. |
| CVE-2025-30399 | Alta (7.5) | 1.1% | — | 13 jun 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2025-21171 | Alta (7.5) | 1.7% | — | 14 ene 2025 | .NET Remote Code Execution Vulnerability |
| CVE-2024-30045 | Media (6.3) | 1.2% | — | 14 may 2024 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2024-21409 | Alta (7.3) | 2.5% | — | 9 abr 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
| CVE-2024-26190 | Alta (7.5) | 3.0% | — | 12 mar 2024 | Microsoft QUIC Denial of Service Vulnerability |
| CVE-2024-21392 | Alta (7.5) | 3.1% | — | 12 mar 2024 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2024-0057 | Crítica (9.8) | 2.8% | — | 9 ene 2024 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability |
| CVE-2023-36013 | Media (6.5) | 1.4% | — | 20 nov 2023 | PowerShell Information Disclosure Vulnerability |
| CVE-2023-21538 | Alta (7.5) | 2.8% | — | 10 ene 2023 | .NET Denial of Service Vulnerability |
| CVE-2022-41121 | Alta (7.8) | 1.1% | — | 13 dic 2022 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2022-41076 | Alta (8.5) | 61% | — | 13 dic 2022 | PowerShell Remote Code Execution Vulnerability |
| CVE-2022-34716 | Media (5.9) | 2.3% | — | 9 ago 2022 | .NET Spoofing Vulnerability |
| CVE-2022-23267 | Alta (7.5) | 5.7% | — | 10 may 2022 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2022-26788 | Alta (7.8) | 0.65% | — | 15 abr 2022 | PowerShell Elevation of Privilege Vulnerability |
| CVE-2022-24512 | Media (6.3) | 1.6% | — | 9 mar 2022 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2021-43896 | Media (5.5) | 2.3% | — | 15 dic 2021 | Microsoft PowerShell Spoofing Vulnerability |
| CVE-2021-41355 | Media (5.7) | 20% | — | 13 oct 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability |
| CVE-2020-8927 | Media (6.5) | 3.2% | — | 15 sept 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying… |
| CVE-2020-0951 | Media (6.7) | 6.6% | — | 11 sept 2020 | <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could… |
| CVE-2020-1108 | Alta (7.5) | 6.3% | — | 21 may 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or… |