Microsoft PowerShell 7.0 (LTS)
Microsoft PowerShell 7.0 (LTS)
The Microsoft PowerShell 7.0 (LTS) reached end of service life on Dec 3, 2022 — Microsoft no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Microsoft PowerShell 7.0 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- powershell
- release
- 7.0
- product Label
- Microsoft PowerShell
- release Label
- 7.0 (LTS)
- codename
- lts
- true
- latest Version
- 7.0.13
- release Date
- 2020-03-04
- maintained
- source Url
- https://endoflife.date/powershell
Lifecycle Dates
- End of Service Life
- Dec 3, 2022
- Last OEM Support
- Dec 3, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Microsoft PowerShell 7.0 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Microsoft PowerShell 7.0 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Microsoft PowerShell 7.0 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Microsoft PowerShell 7.0 (LTS) Support: Frequently Asked Questions
Is the Microsoft PowerShell 7.0 (LTS) still supported?
Microsoft ended support for the Microsoft PowerShell 7.0 (LTS) on Dec 3, 2022 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Microsoft PowerShell 7.0 (LTS) end of service life (EOSL) date?
Microsoft lists the end of service life for the Microsoft PowerShell 7.0 (LTS) as Dec 3, 2022.
Can I keep using the Microsoft PowerShell 7.0 (LTS) after its EOSL date?
Yes. EOSL means Microsoft stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Microsoft PowerShell 7.0 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Microsoft PowerShell 7.0 (LTS)
7 published CVEs affect the Microsoft PowerShell 7.0 (LTS), including 3 rated critical or high severity. Microsoft no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-26788 | HIGH | 7.8 | Apr 15, 2022 | PowerShell Elevation of Privilege Vulnerability |
| CVE-2022-23267 | HIGH | 7.5 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2020-1108 | HIGH | 7.5 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the v |
| CVE-2020-0951 | MEDIUM | 6.7 | Sep 11, 2020 | <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code |
| CVE-2022-24512 | MEDIUM | 6.3 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2022-34716 | MEDIUM | 5.9 | Aug 9, 2022 | .NET Spoofing Vulnerability |
| CVE-2020-8927 | MEDIUM | 5.3 | Sep 15, 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits. |