vendor:
Windows PowerShell ISE
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
Filename Parsing Flaw Remote Code Execution
20
CWE
Product Name: Windows PowerShell ISE
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Windows PowerShell ISE Filename Parsing Flaw Remote Code Execution
Windows PowerShell ISE will execute wrongly supplied code when debugging specially crafted PowerShell scripts that contain array brackets as part of the filename. This can result in ISE executing attacker supplied scripts pointed to by the filename and not the "trusted" PS file currently loaded and being viewed by a user in the host application. This undermines the integrity of PowerShell ISE allowing potential unexpected remote code execution.