CVE-2026-70338: Microsoft PowerShell Security Feature Bypass Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

FAQ

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass Windows Defender Application Control and PowerShell Constrained Language Mode restrictions, allowing untrusted code to run with capabilities those protections are designed to block.

Affected Products (3)

Developer Tools

  • PowerShell 7.4
  • PowerShell 7.5
  • PowerShell 7.6

Acknowledgments

<a href="https://x.com/ayatoshitomi">Ayato Shitomi</a>, 陳宥升 (CheN..) https://github.com/samer666569, MinhNV5 with <a href="https://mbbank.com.vn/">MBBank</a>, <a href="https://www.ymsora.com/">YMsora</a>

Revision History

  • 2026-08-11: Information published.