PT-2020-4389 · Microsoft · Powershellget+2

Published

2020-10-13

·

Updated

2023-12-31

·

CVE-2020-16886

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: PowerShellGet V2 module (affected versions not specified)
Description: The issue is related to security mechanism shortcomings in the PowerShellGet module of the Windows operating system. It allows an attacker to bypass Windows Defender Application Control policy and execute arbitrary code. To exploit this, an attacker must have administrator privileges to install the PowerShellGet V2 module from the PowerShell Gallery and configure the WDAC policy to allow the module to run. This enables the injection and execution of PowerShell scripts with full trust, leading to arbitrary code execution on the machine.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2020-04902
CVE-2020-16886

Affected Products

Powershellget
Windows
Windows Defender Application Control