Privilege Elevation Vulnerability in Windows PowerShell by Microsoft
CVE-2025-49734

7HIGH

What is CVE-2025-49734?

An improper restriction in the communication channel within Windows PowerShell allows an authorized attacker to elevate their privileges locally. This vulnerability can lead to unauthorized access and manipulation of system resources, enabling the attacker to execute commands with higher privileges than initially permitted. Users of Windows PowerShell should ensure that they are using the latest versions and apply any relevant updates or patches as provided by Microsoft to mitigate the risks associated with this vulnerability.

Affected Version(s)

PowerShell 7.4 Unknown 7.4.0 < 7.4.12

PowerShell 7.5 Unknown 7.5.0 < 7.5.3

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8422

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49734 : Privilege Elevation Vulnerability in Windows PowerShell by Microsoft