Description
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Published: 2026-07-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Integer overflow or wraparound in Windows Terminal enables an unauthorized attacker to execute code over a network. The flaw is a classic integer overrun (CWE‑190) that can compromise confidentiality, integrity, and availability by allowing arbitrary code execution on the victim system.

Affected Systems

Microsoft Windows Terminal App is affected. Versions are not specified in the advisory, so all current releases may be vulnerable until patched.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based approach targeting the Windows Terminal service, requiring an attacker to be able to send crafted data to the application. Given the low exploitation probability, the overall risk is moderate for environments that expose the Terminal to external networks.

Generated by OpenCVE AI on July 31, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows Terminal security update from Microsoft.
  • If an update is not yet available, restrict network access to the Windows Terminal service or disable remote connections to the application.
  • Validate and sanitize all input to the Terminal to prevent integer overflow, following general mitigations for CWE‑190.

Generated by OpenCVE AI on July 31, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Title Windows Terminal Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft terminal
Weaknesses CWE-190
CPEs cpe:2.3:a:microsoft:terminal:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft terminal
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Terminal
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:52:43.260Z

Reserved: 2026-07-02T16:05:24.069Z

Link: CVE-2026-59117

cve-icon Vulnrichment

Updated: 2026-07-17T11:00:47.059Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:15:18Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound