CVE-2019-17067: Putty

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.

Affected products

  • Putty Putty: before 0.73 (fixed in 0.73)

Published 2019-10-01. Last modified 2026-06-17.