← Vulnerability feed

Vulnerability record · CVE-2018-8327 · published 11 July 2018

CVE-2018-8327: Microsoft powershell vulnerability

Microsoft · Powershell

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

9.8 CVSS 3.1 Critical EPSS 22% · top 2.4%
9.8CVSS 3.1 base score, v2 10.0
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-0057Microsoft powershell improper input validation vulnerabilityNET, .NET Framework, and Visual Studio Security Feature Bypass VulnerabilityEPSS 2.8%8.8CVE-2026-70337Microsoft powershell relative path traversal vulnerabilityRelative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.EPSS 0.94%8.5CVE-2022-41076Microsoft PowerShell remote code execution flawCVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a…EPSS 61%analysed7.8CVE-2026-50523Microsoft powershell command injection vulnerabilityImproper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute …EPSS 0.32%7.8CVE-2026-70338Microsoft powershell code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…EPSS 0.36%7.8CVE-2026-26143Microsoft powershell improper input validation vulnerabilityImproper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.EPSS 0.47%7.8CVE-2022-41121Microsoft powershell vulnerabilityWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 1.1%7.8CVE-2022-26788Microsoft powershell vulnerabilityPowerShell Elevation of Privilege VulnerabilityEPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2018-8327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.