Microsoft added Security Update Guide entries for CVE-2025-48815 and CVE-2025-48818, with the latter explicitly associated with PowerShell and both listed under Microsoft’s vulnerability disclosure and update ecosystem. The entries identify Microsoft as the assigning CNA and link to standard resources including CVSS guidance, CSAF/API feeds, acknowledgements, and support lifecycle information, confirming the CVEs have been reserved and published in Microsoft’s advisory infrastructure.
The available records provide almost no technical detail: they do not specify affected products or versions, severity, exploitation status, impact, or remediation steps. A related Microsoft advisory reference for CVE-2022-34718 is also present but similarly lacks usable synopsis data in the provided material, leaving defenders with confirmation of the identifiers but little actionable information from the exposed entries alone.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Security Update Guide lists CVE-2025-48818 as a tracked vulnerability entry associated with PowerShell. The excerpt confirms the CVE identifier and Microsoft's role as CNA, but does not include impact, severity, or fix details.
Microsoft's Security Update Guide lists CVE-2025-48815 as a tracked vulnerability entry. The excerpt confirms the CVE identifier and its association with Microsoft's update ecosystem, but provides no technical or remediation details.
Microsoft's Security Update Guide includes an advisory entry for CVE-2022-34718. The provided reference confirms the CVE's presence in Microsoft's product advisory ecosystem but does not include technical details in the excerpt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.