CVE-2016-6167: Putty

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current working directory.

Affected products

  • Putty Putty: version 0.67 only

Published 2017-01-30. Last modified 2026-06-17.