CVE-2026-11967
- EPSS 0.11%
- Veröffentlicht 12.06.2026 13:30:10
- Zuletzt bearbeitet 12.06.2026 16:00:18
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv...
CVE-2026-11879
- EPSS 0.11%
- Veröffentlicht 12.06.2026 13:29:41
- Zuletzt bearbeitet 12.06.2026 16:00:18
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searche...
CVE-2019-25741
- EPSS 0.64%
- Veröffentlicht 04.06.2026 13:22:45
- Zuletzt bearbeitet 04.06.2026 15:00:40
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm session...
- EPSS 0.15%
- Veröffentlicht 17.04.2026 06:16:30
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered...
CVE-2026-25866
- EPSS 0.13%
- Veröffentlicht 09.03.2026 15:24:47
- Zuletzt bearbeitet 06.05.2026 14:23:35
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search pat...
CVE-2025-0714
- EPSS 0.15%
- Veröffentlicht 17.02.2025 12:15:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
The vulnerability exists in the password storage of Mobateks MobaXterm in versions below 25.0. MobaXTerm uses an initialisation vector (IV) consisting only of zero bytes and a master key to encrypt each password individually. In the default configura...
CVE-2024-48200
- EPSS 0.18%
- Veröffentlicht 31.10.2024 19:15:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)
CVE-2022-38336
- EPSS 0.83%
- Veröffentlicht 06.12.2022 00:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:47
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
CVE-2022-38337
- EPSS 0.73%
- Veröffentlicht 06.12.2022 00:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:48
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.
CVE-2021-28847
- EPSS 1.35%
- Veröffentlicht 03.06.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:19
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.