QID 375629

Date Published: 2021-06-17

QID 375629: Putty Denial of Service Vulnerability

PuTTY is a client program for the SSH, Telnet and Rlogin network protocols. It is integrated in multiple applications on multiple operating systems for providing SSH, Telnet, and Rlogin protocol support.

CVE-2021-33500: PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.

Affected Version:
PuTTY version prior to 0.75

QID Detection Logic
This QID checks the vulnerable version of PuTTY by checking the file version of file in registry and also checks in %programfiles%\PuTTY location.

Successful exploitation of this vulnerability may allow an attacker to crash the putty service on the target system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to latest version PuTTY 0.75 Inorder to remediate this vulnerability.

    CVEs related to QID 375629

    Software Advisories
    Advisory ID Software Component Link
    Putty URL Logo www.chiark.greenend.org.uk/~sgtatham/putty/changes.html