CVE-2019-9896

HIGH

PuTTY <0.71 - Code Injection

Title source: llm

Description

In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.

Exploits (1)

nomisec WORKING POC 7 stars
by yasinyilmaz · poc
https://github.com/yasinyilmaz/vuln-chm-hijack

Scores

CVSS v3 7.8
EPSS 0.0216
EPSS Percentile 84.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (3)

putty/putty < 0.71
opensuse/backports_sle
opensuse/leap

Timeline

Published Mar 21, 2019
Tracked Since Feb 18, 2026