PT-2019-4940 · Ultravnc · Ultravnc
Published
2019-03-05
·
Updated
2020-06-12
·
CVE-2019-8266
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UltraVNC revision 1207
Description
The issue is related to improper usage of the
ClientConnection::Copybuffer function in the VNC client code, which can result in out-of-bounds access and potentially allow code execution. This can be exploited via network connectivity, and user interaction is required to trigger the issue. The exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.Recommendations
For UltraVNC revision 1207, update to revision 1208 to resolve the issue. As a temporary workaround, consider restricting network connectivity to minimize the risk of exploitation until the update can be applied.
Fix
Access of Memory Location After End of Buffer
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ultravnc