PT-2022-16854 · Ultravnc · Ultravnc
Jing Qiang
+1
·
Published
2022-03-10
·
Updated
2023-03-01
·
CVE-2022-24750
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UltraVNC versions prior to 1.3.8.0
Description
A vulnerability has been found in UltraVNC, a free and open source remote pc access software, where the DSM plugin module allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system. The vulnerability has been fixed to allow loading of plugins from the installed directory.
Recommendations
For versions prior to 1.3.8.0, upgrade to version 1.3.8.1 to resolve the issue.
If an upgrade is not possible, do not install and run UltraVNC server as a service.
As a temporary workaround, consider creating a scheduled task on a low privilege account to launch WinVNC.exe instead.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ultravnc