Impact
The vulnerability is a relative path traversal flaw in Windows PowerShell that permits an authorized attacker to execute code remotely over the network. This flaw is a classic example of CWE-23 and can lead to full compromise of the affected system, allowing the attacker to run arbitrary code with the privileges of the user executing the malicious PowerShell script.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2012 (full and core), Windows Server 2012 R2 (full and core), Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 (full and core).
Risk and Exploitability
The CVSS score of 8 classifies this as a high‑severity flaw, and the EPSS score of <1% indicates a very low current likelihood of exploitation, though the risk remains significant for systems with an authorized user who could leverage the attack. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation campaigns. Attackers would need authorized network access to the target and the ability to trigger the relative path traversal in PowerShell, after which arbitrary code would run with local user privileges.
OpenCVE Enrichment