CVE-2024-45301

MEDIUM

mintty 2.3.6-3.7.4 - Unauthenticated NTLM Hash Exposure via Escape Sequence

Title source: llm
STIX 2.1

Description

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an ntlm hash out of the victim's machine to an attacker controlled remote host. An attacker can use password cracking tools or NetNTLMv2 hashes to Pass the Hash. Version 3.7.5 fixes the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 15.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
mintty/mintty >= 2.3.6, < 3.7.5
Published Nov 12, 2025
Tracked Since Feb 18, 2026