In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9896.json"