Executive brief
A vulnerability exists in the Microsoft Telnet Client, a tool used to connect to remote computers over a network. An attacker could exploit this flaw to access sensitive information that should normally be protected. Successful exploitation requires a user to connect to a malicious server, which could lead to data disclosure or minor service instability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Telnet Client. The flaw is triggered when the client processes specially crafted data sent from a malicious Telnet server. While the attack vector is network-based, it requires user interaction, specifically that a user initiates a connection to a server controlled by the attacker. Successful exploitation allows the attacker to read sensitive information from the process memory and potentially cause a partial denial of service. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Telnet Client
Timeline
- 2026-05-12: advisory: Initial disclosure by Microsoft and NVD.