PatchSiren

Putty CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Putty CVE published 2017-01-30

CVE-2016-6167

CVE-2016-6167 describes an untrusted search path issue in PuTTY beta 0.67. According to the NVD record, a local attacker can abuse a Trojan horse UxTheme.dll or ntmarta.dll placed in the current working directory to trigger DLL hijacking and arbitrary code execution. The issue is rated High (CVSS 7.8) and maps to CWE-426.