Code Injection in PowerShell - CVE-2026-70338
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to improper control of generation of code ('code injection') in Microsoft PowerShell when processing crafted local input. A remote attacker can supply crafted input to bypass a security feature.
User interaction is required. Successful exploitation could bypass Windows Defender Application Control and PowerShell Constrained Language Mode restrictions, allowing untrusted code to run with capabilities those protections are designed to block.