Skip to content
PowerShell is affected by 2 Critical Vulnerabilities published in November

PowerShell is affected by 2 Critical Vulnerabilities published in November

Written By Anoop C Nair
Last Updated November 20, 2023
Posted In Windows 11
SHARE

Let’s get more details on the following PowerShell is affected by 2 Critical Vulnerabilities published in 2023 November. As per Microsoft’s latest CVE revision, the PowerShell 7.2, 7.3, and 7.4 versions are also affected by the Visual Studio Remote Code Execution Vulnerabilities.

Microsoft published 2 PowerShell related vulnerabilities in the month of November 2023. There was 3 Zero Day Vulnerabilities released as part of Nov patch Tuesday. CVE-2023-36013 and CVE-2023-36049 are the two vulnerabilities published by Microsoft.

Apart from these 2 updated CVEs, there are 59 other vulnerabilities. Also, Microsoft released Windows 11 KB5030217 KB5030219 and Windows 10 KB5030211 latest cumulative updates (LCU) of September 2023. It’s highly recommended to update the PowerShell as discussed in the below.

On September 20, 2023, Microsoft added additional details to 5 CVEs published on 12th September. These 5 CVEs are CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796, and CVE-2023-36799. You can get more details on impacts related to Windows and Linux operating systems.

Patch My PC

As per Microsoft, the revised Security Updates table includes PowerShell 7.2 and PowerShell 7.3 because these versions of PowerShell 7 are affected by this vulnerability. These are critical and important vulnerabilities, as per Microsoft.

PowerShell is affected by 2 Critical Vulnerabilities published in November
PowerShell is affected by 2 Critical Vulnerabilities published in November – Fig.

PowerShell Information Disclosure Vulnerability – CVE-2023-36013

PowerShell Information Disclosure Vulnerability – CVE-2023-36013 published with CVSS:3.1 6.5 / 5.7. The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, and other sensitive information.

ProductFix Download
PowerShell 7.4https://github.com/PowerShell/Announcements/issues/55
PowerShell 7.3https://github.com/PowerShell/Announcements/issues/55
PowerShell 7.2https://github.com/PowerShell/Announcements/issues/55
PowerShell is affected by 2 Critical Vulnerabilities published in November – Table 2

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability – CVE-2023-36049

To exploit this vulnerability an attacker would have to inject arbitrary commands to the FTP server. The type of information that could be disclosed if an attacker successfully exploited this vulnerability would be access controls on the server, allowing for read or write abilities.

Revised the Security Updates table for CVE-2023-36049 includes PowerShell 7.2, PowerShell 7.3, and PowerShell 7.4 because these versions of PowerShell 7 are affected by this vulnerability.

PowerShell 7 is affected by 5 Critical Vulnerabilities

The 5 September 2023 vulnerabilities impacting PowerShell 7.x versions are CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796, and CVE-2023-36799. Check out the table below to understand whether the impact is only for Windows devices, Linux, and macOS devices.

CVE-2023-36799 (only for Linux): A vulnerability exists in .NET where reading a maliciously crafted X.509 certificate may result in Denial of Service. This issue only affects Linux systems.

  • .NET released multiple security updates for issues involving Microsoft.DiaSymReader.Native.*.dll.
  • PowerShell 7 removed these binaries from the initial release of 7.3 and 7.2.12.
  • The currently supported versions of PowerShell 7 are not affected.
Impacted Operating SystemNot Impacted OSImpacted PowerShell VersionFixed inCVEs
WindowsmacOS and Linux7.27.2.12CVE-2023-36796, CVE-2023-36793, CVE-2023-36794, CVE-2023-36792
LinuxmacOS and Windows7.27.2.14CVE-2023-36799
LinuxmacOS and Windows7.37.3.7CVE-2023-36799
PowerShell is affected by 2 Critical Vulnerabilities published in November – Table 1

FIX: Update PowerShell Versions to 7.2.12 and 7.3.7

To fix these .Net related vulnerabilities impacting PowerShell versions running on Windows and Linux operating systems, you need to update the PowerShell versions to 7.2.12 and 7.3.7, respectively.

On the Windows operating system, the Microsoft Update feature of PowerShell allows you to get the latest PowerShell 7 updates in your traditional Microsoft Update (MU) management flow. You can use Windows Update for Business (WUfB), WSUS, SCCM, or the interactive MU dialogue in Settings.

PowerShell 7 is affected by 5 Critical Vulnerabilities published in September Fig. 2
PowerShell 7 is affected by 5 Critical Vulnerabilities published in September Fig. 2

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Security

Microsoft Fixes 570 Security Vulnerabilities and 3 Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Key Takeaways Microsoft Fixes 570 Security Vulnerabilities and 3 Zero-Day Vulnerabilities in July 2026 Patch Tuesday! Microsoft fixed 3 zero-day vulnerabilities as part of the July 2026 Patch Tuesday updates. Two of them, CVE-2026-56164 (Microsoft SharePoint Server Elevation of Privilege) and CVE-2026-56155 (Active Directory Federation Services Elevation of Privilege), were actively exploited before the security […]

AC Anoop C Nair 29 min read
Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Windows 11

Boost Productivity with Zoom Workplace on Windows 11 | Setup Guide for Meetings Chat Calls and Collaboration

Key Takeaways Hey, let’s learn about Boost Productivity with Zoom Workplace on Windows 11 | Setup Guide for Meetings Chat Calls and Collaboration. Zoom workplace is an AI-powered collaboration app used for online meetings, team collaboration, and video calls. This application helps to conduct meetings Including chat and messaging, screen sharing and Calendar Integration. Boost […]

AC Anoop C Nair 35 min read
Windows 11

13 Windows AI Features to Turn Off for Better Privacy

Key takeaways Hey, let’s discuss about 13 Windows AI features to turn off for better privacy. AI is widely used in modern systems such as Windows 11 to automate tasks, improve productivity, and enhance user experience. However, AI also has several disadvantages. It may raise privacy concerns because personal data can be collected and analysed […]

AC Anoop C Nair 15 min read