PowerShell 2.0, originally released with Windows 7, has been identified as a significant attack vector due to its lack of modern security features, including script block logging, constrained language mode, and Anti-Malware Scan Interface (AMSI) integration. The removal, announced in Windows 11 Insider Preview Build 27891 released to the Canary Channel on July 3, 2025, addresses longstanding architectural and security vulnerabilities that have plagued the legacy PowerShell version. These missing security controls have made PowerShell 2.0 a preferred tool for attackers seeking to bypass modern Windows Defender protections and execute malicious scripts undetected. Microsoft removed PowerShell 2.0 from Windows 11 Build 27891 due to critical vulnerabilities and missing modern security features. Build 27891 also fixes "Reset this PC," taskbar rendering, Windows Update downloads, and Task Manager issues. PowerShell 2.0 allowed attackers to bypass Windows Defender using powershell.exe -version 2 downgrade commands.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 07 Jul 2025 14:20:12 +0000