CVE-2025-54100
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.
- Affected products
- Windows, Windows Powershell
- Microsoft Windows 10 1607
- < 10.0.14393.8688
- Microsoft Windows 10 1809
- < 10.0.17763.8146
- Microsoft Windows 10 21h2
- < 10.0.19044.6691
- Microsoft Windows 10 22h2
- < 10.0.19045.6691
- Microsoft Windows 11 23h2
- < 10.0.22631.6345
- Microsoft Windows 11 24h2
- < 10.0.26100.7456
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.6% (74th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2025-12-09
CVE-2025-54100 at NVD
8 known exploits for CVE-2025-54100
Proof-of-concept code and exploit modules indexed by Sploitus