PT-2002-1979 · Tridiavnc+2 · Tridiavnc+2

Published

2002-08-23

·

Updated

2016-10-18

·

CVE-2002-0971

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: TightVNC (affected versions not specified) VNC (affected versions not specified) TridiaVNC (affected versions not specified)
Description: The issue allows local users to execute arbitrary code as LocalSystem by utilizing the Win32 Messaging System. This is done by bypassing the VNC GUI to access the "Add new clients" dialogue box.
Recommendations: For TightVNC, consider restricting access to the "Add new clients" dialogue box until a fix is available. For VNC, restrict local user access to sensitive features to minimize the risk of exploitation. For TridiaVNC, as a temporary workaround, limit the use of the Win32 Messaging System to prevent bypassing the VNC GUI.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0971

Affected Products

Tightvnc
Tridiavnc
Vnc