PT-2020-4389 · Microsoft · Powershellget+2
Published
2020-10-13
·
Updated
2023-12-31
·
CVE-2020-16886
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PowerShellGet V2 module (affected versions not specified)
Description:
The issue is related to security mechanism shortcomings in the PowerShellGet module of the Windows operating system. It allows an attacker to bypass Windows Defender Application Control policy and execute arbitrary code. To exploit this, an attacker must have administrator privileges to install the PowerShellGet V2 module from the PowerShell Gallery and configure the WDAC policy to allow the module to run. This enables the injection and execution of PowerShell scripts with full trust, leading to arbitrary code execution on the machine.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powershellget
Windows
Windows Defender Application Control