A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the Telnet protocol that does not correctly opt in to NTLM credential-reflection protections to ensure that a user's credentials are not reflected back and used against the user, which could allow attackers to execute arbitrary code by tricking a user into connecting to a specially crafted Telnet server.
Note: This vulnerability is currently being exploited in targeted attacks.