Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code
## Security Update: Windows PowerShell Vulnerability
Security Update: Windows PowerShell Vulnerability
A significant security update has been released to address a vulnerability in Windows PowerShell that allows attackers to execute malicious code on affected systems. This vulnerability, identified as CVE-2025-54100, was made public on December 9, 2025, posing a substantial risk to organizations globally.
The vulnerability arises from improper neutralization of special elements within Windows PowerShell during command injection attacks. It enables unauthorized attackers to execute arbitrary code locally by using specially crafted commands.
Microsoft assesses the likelihood of real-world exploitation as low, though the vulnerability has been publicly disclosed. Exploitation requires local access and user interaction, typically involving users opening malicious files or executing suspicious commands.
The vulnerability is classified with a CVSS score of 7.8, indicating its severity. It affects various Windows operating systems, including Windows 10, Windows 11, and Windows Server versions from 2008 to 2025.
Microsoft has released security updates across multiple platforms. Organizations using Windows Server 2025, Windows 11 versions 24H2 and 25H2, and Windows Server 2022 should prioritize updates using KB5072033 or KB5074204. Users on Windows 10 and earlier versions require different updates, such as KB5071546 or KB5071544.
System administrators should be aware that most security updates necessitate a system reboot after installation. Additionally, installing updates KB5074204 or KB5074353 will trigger a security warning when using the Invoke-WebRequest command. Microsoft advises using the UseBasicParsing switch to prevent script code execution from web content.
This vulnerability, identified as CVE-2025-54100, was made public on December 9, 2025, posing a substantial risk to organizations globally.
Organizations are also encouraged to implement security guidelines in KB5074596 for PowerShell 5.1 to mitigate script execution risks. This update reflects the collaborative efforts between Microsoft and the security community to protect Windows users from emerging threats.
Details Information
CVE Identifier CVE-2025-54100
Attack Vector Local
CVSS Score 7.8
Impact Type Remote Code Execution
Affected Component Windows PowerShell
Based on reporting by Cyber Security News.
