
Cloud Vulnerability DB
A community-led vulnerabilities database
Mintty before version 3.4.5 contains a denial of service vulnerability (CVE-2021-28848) that allows remote servers to cause a Windows GUI hang. The vulnerability occurs when a remote server repeatedly tells the Mintty window to change its title at high speed, resulting in numerous SetWindowTextA or SetWindowTextW calls without implementing any delay mechanism for processing title changes (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified under CWE-770 (Allocation of Resources Without Limits or Throttling). The vulnerability stems from the lack of rate limiting or throttling mechanism when processing window title change requests (NVD).
When exploited, this vulnerability can cause a denial of service condition by freezing the Windows GUI interface. The attack requires no user interaction and can be executed remotely, potentially affecting system availability (NVD).
The vulnerability is exploitable remotely without requiring authentication or user interaction. An attacker can trigger the vulnerability by sending rapid window title change requests to a Mintty terminal (NVD).
The vulnerability was fixed in Mintty version 3.4.5 by implementing a usleep(1000) delay when processing window title changes. Users should upgrade to version 3.4.5 or later to mitigate this vulnerability (Mintty Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."