Impact
Windows PowerShell contains an improper limitation of pathname to a restricted directory, enabling an authorized attacker to perform path traversal and elevate privileges on the system. The flaw allows execution of commands that bypass normal directory access controls, granting an attacker higher privilege levels. This vulnerability is classified as CWE-22.
Affected Systems
The vulnerability affects multiple Microsoft Windows operating systems. It is present on Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and on Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score is 8.0, indicating high severity, while no EPSS information is available and the vulnerability is not listed in CISA KEV. The likely attack vector is a network‑based authorized user who can execute PowerShell commands. The flaw can be exploited by crafting a pathname that traverses out of the intended directory, allowing the attacker to run elevated commands. Successful exploitation results in privilege escalation, potentially granting full control over the target machine.
OpenCVE Enrichment