ThreatCluster

Critical Windows PowerShell 0-Day Vulnerability Disclosed

First seen 10 Dec 2025, 13:46 UTC GbhackersCybersecuritynewsCyberpress 31

Article Content

Browse articles
ThreatCluster

Microsoft has disclosed a new 0-day vulnerability in Windows PowerShell, tracked as CVE-2025-54100, which allows attackers to execute arbitrary code on affected systems. The flaw arises from improper neutralization of special elements during command injection attacks and poses a significant risk to organizations globally. The vulnerability was publicly disclosed on December 9, 2025.