Junglewise Threat Intelligence

CVE-2026-69431: Telnet Client heap-based buffer overflow

CVE-2026-69431 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Telnet Client, a legacy network protocol application used for remote terminal access, contains a heap-based buffer overflow vulnerability that allows an attacker to execute arbitrary code on an affected system over the network without authentication. This flaw creates a significant risk for any organization still using Telnet for network administration or access, potentially enabling full system compromise and unauthorized access to sensitive data.

Technical details

A heap-based buffer overflow exists in Telnet Client, triggered when processing network input. The vulnerability allows an unauthenticated attacker to overflow a heap buffer by sending specially crafted Telnet protocol data, leading to remote code execution. The attack is network-reachable and requires no prior authentication or user interaction. An attacker can achieve arbitrary code execution in the context of the Telnet Client process. Patches are expected to be available from the vendor; consult the Microsoft Security Response Center for remediation guidance.

Affected products

  • Microsoft Telnet Client

Timeline

  • 2026-09-08: disclosed

References