CVE-2025-54100: PowerShell Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.
Other sources
PowerShell Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54100?
CVE-2025-54100 is assessed as a critical vulnerability due to its ability to allow unauthorized code execution via command injection.
How do I fix CVE-2025-54100?
To mitigate CVE-2025-54100, apply the latest security patches provided by Microsoft for affected Windows Server and Windows operating systems.
What systems are affected by CVE-2025-54100?
CVE-2025-54100 affects various versions of Windows Server, including 2012, 2012 R2, 2008, 2008 R2, as well as Windows 10 and Windows 11.
Can CVE-2025-54100 be exploited remotely?
Yes, CVE-2025-54100 can be exploited remotely if the attacker has access to run commands in Windows PowerShell.
What is the impact of CVE-2025-54100?
The impact of CVE-2025-54100 includes the potential for attackers to execute arbitrary code on the affected system, leading to data breaches or system compromise.