← Vulnerability feed

Vulnerability record · CVE-2022-41076 · published 13 December 2022

CVE-2022-41076: Microsoft PowerShell remote code execution flaw

Microsoft · Powershell

CVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a one-line description and no root-cause detail, so the exact mechanism is unknown, but the scope change and full confidentiality, integrity and availability impact mean a successful attack can compromise the host beyond the vulnerable component.

8.5 CVSS 3.1 High EPSS 61% · top 0.9%
8.5CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

PowerShell Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.5 with network reachability, low privileges required and full scope-changed impact, plus a very high EPSS score, outweigh the absence of confirmed exploitation and thin technical detail.

What it is

CVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a one-line description and no root-cause detail, so the exact mechanism is unknown, but the scope change and full confidentiality, integrity and availability impact mean a successful attack can compromise the host beyond the vulnerable component.

Impact

An attacker who can reach the vulnerable PowerShell path can execute arbitrary code with the privileges of the exploited context, gaining full control over confidentiality, integrity and availability of the affected system.

Attack surface

The vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user or service can attempt it remotely. The high attack complexity (AC:H) indicates conditions must be met for success, and the scope change (S:C) means impact can extend past PowerShell itself.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit or proof-of-concept, so there is no confirmed in-the-wild exploitation in this record. EPSS is high at 0.605 (99.1st percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply the Microsoft security update for CVE-2022-41076 on all affected Windows and PowerShell installations as the first action.
  • Inventory PowerShell versions and Windows builds across clients and servers, including legacy Windows 7, 8.1, RT 8.1, Server 2008 and Server 2012, and prioritize unsupported or rarely patched systems.
  • Restrict network exposure of PowerShell remoting and management endpoints to trusted administrative networks and hosts.
  • Enforce least privilege so low-privileged accounts cannot reach the vulnerable code path, and review service accounts with PowerShell access.
  • Monitor Microsoft advisories for updated guidance since the record lacks root-cause and affected-version detail.

Detection

  • Alert on unusual PowerShell process creation, especially powershell.exe spawning child processes or network connections from server workloads.
  • Monitor PowerShell remoting (WinRM) and module/script block logging for anomalous sessions from low-privileged accounts.
  • Baseline and review PowerShell script block and transcription logs for unexpected encoded or obfuscated commands.
  • Track patch state of PowerShell and Windows builds against the Microsoft update guide to find unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-41076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2022-41076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.