A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 26.2 is able to mitigate this issue. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-6421 is a local privilege escalation vulnerability in MobaXterm Home Edition up to version 26.1 affecting the msimg32.dll library through uncontrolled search path manipulation. The vulnerability requires local access and high attack complexity but has been publicly disclosed and is exploitable.
ثغرة في مكتبة msimg32.dll بـ MobaXterm Home Edition تسمح بمعالجة مسار بحث غير محكوم، مما قد يؤدي إلى تنفيذ كود محلي. تتطلب الثغرة وصول محلي للنظام وتتمتع بتعقيد هجوم عالي. تم إصدار إصلاح في الإصدار 26.2.
هذا الثغرة في MobaXterm Home Edition الإصدار 26.1 وما قبله تؤثر على مكتبة msimg32.dll من خلال مسار بحث غير محكوم. تتطلب الثغرة وصول محلي وتعقيد هجوم عالي لكنها تم الكشف عنها علنا.
Upgrade MobaXterm Home Edition to version 26.2 or later immediately. Restrict local user access to systems running vulnerable versions. Implement application whitelisting and monitor for suspicious DLL loading activities.
قم بترقية MobaXterm Home Edition إلى الإصدار 26.2 أو أحدث فوراً. قيد وصول المستخدمين المحليين للأنظمة التي تشغل الإصدارات الضعيفة. طبق قائمة التطبيقات المسموحة ومراقبة أنشطة تحميل DLL المريبة.