Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an ntlm hash out of the victim's machine to an attacker controlled remote host. An attacker can use password cracking tools or NetNTLMv2 hashes to Pass the Hash. Version 3.7.5 fixes the issue.
References
Configurations
No configuration.
History
12 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-12 19:15
Updated : 2025-11-14 16:42
NVD link : CVE-2024-45301
Mitre link : CVE-2024-45301
CVE.ORG link : CVE-2024-45301
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
