PT-2025-2686 · Mintty · Mintty

Published

2025-01-10

·

Updated

2025-11-12

·

CVE-2024-45301

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mintty (affected versions not specified)
Description The issue is related to improper input validation in Mintty's path conversion, allowing remote attackers to relay NTLM credentials on affected installations. This requires user interaction, where the target must visit a malicious link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-45301
GHSA-JF4M-M6RV-P6C5
ZDI-25-026

Affected Products

Mintty