Arbitrary Code Execution in MobaXterm Personal Edition by Mobatek
CVE-2026-11967
8.5HIGH
What is CVE-2026-11967?
The MobaXterm Personal Edition (Portable), specifically in version 26.3 (Build 5154), is susceptible to a vulnerability that allows for arbitrary code execution. This occurs when the application loads a malicious DLL file placed in the same directory as its executable. During the startup process, MobaXterm automatically loads the winspool.drv library from this location, enabling an attacker with local access to execute crafted DLLs alongside the application. Users should be aware of this risk and take appropriate measures to secure their installations.
Affected Version(s)
MobaXterm Personal Edition (Portable) 26.3
MobaXterm Personal Edition (Portable) 26.4
