Vulnerability Description
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobatek | Mobaxterm | < 21.0 |
References
- https://mobaxterm.mobatek.net/download-home-edition.htmlProductRelease NotesVendor Advisory
- https://mobaxterm.mobatek.net/preview.htmlRelease NotesVendor Advisory
- https://mobaxterm.mobatek.net/download-home-edition.htmlProductRelease NotesVendor Advisory
- https://mobaxterm.mobatek.net/preview.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2021-28847?
CVE-2021-28847 is a vulnerability with a CVSS score of 7.5 (HIGH). MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA o...
How severe is CVE-2021-28847?
CVE-2021-28847 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28847?
Check the references section above for vendor advisories and patch information. Affected products include: Mobatek Mobaxterm.