PT-2009-1012 · Realvnc+1 · Realvnc Vnc Free Edition+4
Published
2009-01-16
·
Updated
2022-06-10
·
CVE-2008-4770
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealVNC VNC Free Edition versions 4.0 through 4.1.2
RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2
RealVNC VNC Personal Edition versions P4.0 through P4.4.2
Description
The issue allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type." This is due to a problem in the
CMsgReader::readRect function in the VNC Viewer component. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.Recommendations
For RealVNC VNC Free Edition versions 4.0 through 4.1.2, update to a version outside of this range to resolve the issue.
For RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2, update to a version outside of this range to resolve the issue.
For RealVNC VNC Personal Edition versions P4.0 through P4.4.2, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the VNC Viewer component until a patch is available.
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realvnc Vnc Enterprise Edition
Realvnc Vnc Free Edition
Realvnc Vnc Personal Edition
Red Hat
Vnc Viewer