CVE-2022-26788: high-severity vulnerability in Microsoft PowerShell 7.0
PowerShell Elevation of Privilege Vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
PowerShell Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · PowerShell 7.0Microsoft · PowerShell 7.1Microsoft · PowerShell 7.2Microsoft · Windows 10 Version 1507Microsoft · Windows 10 Version 1607Microsoft · Windows 10 Version 1809Microsoft · Windows 10 Version 1909Microsoft · Windows 10 Version 20H2Microsoft · Windows 10 Version 21H1Microsoft · Windows 10 Version 21H2Microsoft · Windows 11 version 21H2Microsoft · Windows 8.1Microsoft · Windows Server 2008 R2 Service Pack 1Microsoft · Windows Server 2008 R2 Service Pack 1 (Server Core installation)Microsoft · Windows Server 2012Microsoft · Windows Server 2012 R2Microsoft · Windows Server 2012 R2 (Server Core installation)Microsoft · Windows Server 2012 (Server Core installation)Microsoft · Windows Server 2016Microsoft · Windows Server 2016 (Server Core installation)Microsoft · Windows Server 2019Microsoft · Windows Server 2019 (Server Core installation)Microsoft · Windows Server 2022Microsoft · Windows Server version 20H2Related CVEs — Microsoft PowerShell 7.0
In the same product, most dangerous first.
CVE-2022-41076HIGHPowerShell Remote Code Execution VulnerabilityEPSS 60.5%CVE-2021-41355MEDIUM.NET Core and Visual Studio Information Disclosure VulnerabilityEPSS 20.3%CVE-2020-0951MEDIUMWindows Defender Application Control Security Feature Bypass VulnerabilityEPSS 6.6%CVE-2020-1108—.NET Core & .NET Framework Denial of Service VulnerabilityEPSS 6.4%CVE-2022-23267HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 5.7%CVE-2023-36799MEDIUM.NET Core and Visual Studio Denial of Service VulnerabilityEPSS 4.9%