Microsoft Windows PowerShell Improper Communication Channel Restriction Privilege Escalation Vulnerability

Vulnerability

A vulnerability in Windows PowerShell has been identified, allowing an authorized attacker to locally elevate privileges. This issue arises from an improper restriction of communication channels, which could enable the attacker to hijack PowerShell Direct sessions intended for admin-guest VM interactions. The vulnerability affects multiple Windows versions, including Windows 10, Windows 11, Windows Server 2016, and Windows Server 2025.

Impact

Exploitation of this vulnerability could allow an attacker to gain unauthorized access to PowerShell Direct sessions, impersonating an admin user and potentially manipulating operations on a guest virtual machine.

Remediation

Users can apply the security update available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5065427, KB5065431, KB5065426, and KB5065474.

Added: Sep 9, 2025, 7:01 PM
Updated: Sep 9, 2025, 7:01 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
2.9
remediation
8.3
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.