Executive brief
MobaXterm is a popular Windows application used by IT professionals for remote terminal access and network management. A security flaw in the portable version allows an attacker with access to the computer to place a malicious file in a temporary folder that the application uses during startup. If successful, the attacker can take full control of the application and the user's session, potentially leading to data theft or further system compromise.
Technical details
A DLL hijacking vulnerability (CWE-427) exists in MobaXterm Personal Edition (Portable) version 26.3. The application's startup routine searches for specific dynamic-link libraries (DLLs) in a predictable temporary directory that is user-modifiable before checking secure system paths. An attacker with local access can place a malicious DLL in this directory to achieve arbitrary code execution with the privileges of the user running the application. This vulnerability has been addressed in version 26.4.
Affected products
- Mobatek MobaXterm Personal Edition (Portable) 26.3 (Build 5154)
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Fixed in version 26.4