ZeroHour

CVE-2019-16305

PoC
CVSS 3.1
8.8 high
EPSS
7%p94
Published
()
Modified
Description

In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appears asking for further confirmation. If this is also accepted, command execution is achieved, as demonstrated by the MobaXterm://`calc` URI.

Vendors
mobatek
Products
mobaxterm
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.