Junglewise Threat Intelligence

CVE-2026-11967: Mobatek MobaXterm DLL hijacking in winspool.drv loading

CVE-2026-11967 · Severity: info · CVSS 8.5 · Published 2026-06-12

Technologies: Mobatek MobaXterm. Vendors: Mobatek.

Executive brief

MobaXterm Personal Edition (Portable) is a popular network tool and terminal emulator for Windows. A security flaw allows an attacker with local access to the computer to run malicious code by placing a specifically named file in the same folder as the application. When a user starts the program, it mistakenly runs the attacker's file, potentially leading to a full system compromise or unauthorized data access.

Technical details

A DLL hijacking vulnerability (CWE-427) exists in MobaXterm Personal Edition (Portable) version 26.3 (Build 5154). The application's startup routine utilizes an uncontrolled search path, causing it to attempt to load the 'winspool.drv' library from the application's current working directory before searching secure system paths. An attacker with local file system access can place a malicious DLL with this name alongside the portable executable. When the victim launches the application, the malicious code is executed with the privileges of the user. This has been addressed in version 26.4.

Affected products

  • Mobatek MobaXterm Personal Edition (Portable) 26.3 (Build 5154)

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched: Fixed in version 26.4

References

Related threats