Impact
The flaw originates from improper control of code generation in Microsoft PowerShell (CWE‑94), enabling an attacker with local access to inject and run arbitrary code that can circumvent the built‑in security feature. The result is a local bypass of the security mechanism, which could allow further malicious actions on the affected system.
Affected Systems
Microsoft PowerShell versions 7.4, 7.5, and 7.6 are affected by this vulnerability. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.8 categorizes the issue as high severity, while an EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not included in CISA’s KEV catalog. Attackers would need local access to craft and execute malicious PowerShell code; the description infers that the feature is bypassed through local code injection.
OpenCVE Enrichment