QID 379098

Date Published: 2023-12-19

QID 379098: MobaTek MobaXterm Denial of Service (DoS) Vulnerability

MobaXterm is an enhanced terminal for Windows with an X11 server, a tabbed SSH client and several other network tools for remote computing (VNC, RDP, telnet, rlogin). MobaXterm brings all the essential Unix commands to Windows desktop, in a single portable exe file which works out of the box.

CVE-2021-28847: MobaXterm allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.

Affected Versions:
MobaTek MobaXterm before version 21.0

QID Detection Logic(Authenticated):
This checks for vulnerable version of MobaXtrem.exe file.

Successful exploitation of this Vulnerability allows remote servers to cause a denial of service

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has issued a fix.
    For more information visit MobaXterm

    CVEs related to QID 379098

    Software Advisories
    Advisory ID Software Component Link
    MobaXterm URL Logo mobaxterm.mobatek.net/download-home-edition.html