Code Injection in PowerShell - CVE-2026-70338

 

Code Injection in PowerShell - CVE-2026-70338

Published: August 12, 2026


Vulnerability identifier: #VU142002
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70338
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass a security feature.

The vulnerability exists due to improper control of generation of code ('code injection') in Microsoft PowerShell when processing crafted local input. A remote attacker can supply crafted input to bypass a security feature.

User interaction is required. Successful exploitation could bypass Windows Defender Application Control and PowerShell Constrained Language Mode restrictions, allowing untrusted code to run with capabilities those protections are designed to block.


Affected software

PowerShell

How to mitigate CVE-2026-70338

Install security update from vendor's website.

PowerShell - update to 7.4.19.0

External References

Related Security Bulletins