Impact
A server‑side request forgery flaw in Microsoft PowerShell Core can allow an unauthorized attacker to cause the host to send arbitrary HTTP requests, potentially disclosing sensitive information over a network. The vulnerability is classified as CWE‑918 and does not require elevated privileges on the target system.
Affected Systems
Microsoft PowerShell 7.4, 7.5 and 7.6 are affected.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, yet the EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require an attacker who can execute PowerShell commands to trigger the SSRF behavior, potentially revealing internal or external data. No publicly documented exploits or specific conditions are known.
OpenCVE Enrichment