Junglewise Threat Intelligence

CVE-2026-59117: Microsoft Windows Terminal integer overflow remote code execution

CVE-2026-59117 · Severity: high · CVSS 7.5 · Published 2026-07-16

Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Terminal application could allow a remote attacker to execute malicious code on a user's computer. Windows Terminal is a modern host application for command-line tools like Command Prompt and PowerShell. If exploited, an attacker could gain unauthorized access to the system, potentially leading to data theft or full system compromise, though the attack requires some level of user interaction.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists within the Microsoft Windows Terminal App. The flaw is reachable over the network and can be exploited by an unauthenticated attacker, though the CVSS vector indicates high attack complexity and a requirement for user interaction (UI:R). Successful exploitation allows for remote code execution (RCE) with the privileges of the user running the terminal application. Microsoft has acknowledged the issue and released information via their Security Update Guide.

Affected products

  • Microsoft Windows Terminal App All versions

Timeline

  • 2026-07-16: disclosed: Initial disclosure by Microsoft and NVD publication.

References

Related threats