Vulnerability record · CVE-2022-41076 · published 13 December 2022
CVE-2022-41076: Microsoft PowerShell remote code execution flaw
Microsoft · Powershell
CVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a one-line description and no root-cause detail, so the exact mechanism is unknown, but the scope change and full confidentiality, integrity and availability impact mean a successful attack can compromise the host beyond the vulnerable component.
Description
PowerShell Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.5 with network reachability, low privileges required and full scope-changed impact, plus a very high EPSS score, outweigh the absence of confirmed exploitation and thin technical detail.
What it is
CVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a one-line description and no root-cause detail, so the exact mechanism is unknown, but the scope change and full confidentiality, integrity and availability impact mean a successful attack can compromise the host beyond the vulnerable component.
Impact
An attacker who can reach the vulnerable PowerShell path can execute arbitrary code with the privileges of the exploited context, gaining full control over confidentiality, integrity and availability of the affected system.
Attack surface
The vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user or service can attempt it remotely. The high attack complexity (AC:H) indicates conditions must be met for success, and the scope change (S:C) means impact can extend past PowerShell itself.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit or proof-of-concept, so there is no confirmed in-the-wild exploitation in this record. EPSS is high at 0.605 (99.1st percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2022-41076 on all affected Windows and PowerShell installations as the first action.
- Inventory PowerShell versions and Windows builds across clients and servers, including legacy Windows 7, 8.1, RT 8.1, Server 2008 and Server 2012, and prioritize unsupported or rarely patched systems.
- Restrict network exposure of PowerShell remoting and management endpoints to trusted administrative networks and hosts.
- Enforce least privilege so low-privileged accounts cannot reach the vulnerable code path, and review service accounts with PowerShell access.
- Monitor Microsoft advisories for updated guidance since the record lacks root-cause and affected-version detail.
Detection
- Alert on unusual PowerShell process creation, especially powershell.exe spawning child processes or network connections from server workloads.
- Monitor PowerShell remoting (WinRM) and module/script block logging for anomalous sessions from low-privileged accounts.
- Baseline and review PowerShell script block and transcription logs for unexpected encoded or obfuscated commands.
- Track patch state of PowerShell and Windows builds against the Microsoft update guide to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-41076 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.