Vulnerability Description
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an attacker with local access can place a specially crafted DLL alongside the executable to be executed when the victim launches the application.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-11967?
CVE-2026-11967 is a documented vulnerability. MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because th...
How severe is CVE-2026-11967?
CVSS scoring is not yet available for CVE-2026-11967. Check NVD for updates.
Is there a patch for CVE-2026-11967?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.