CyberICT

CVE-2026-70338

Microsoft · Published August 11, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft PowerShell Security Feature Bypass Vulnerability. Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Affected Products

  • PowerShell 7.4
  • PowerShell 7.5
  • PowerShell 7.6

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C