PT-2026-23987 · Microsoft+1 · Windows+1

Haehanse

+1

·

Published

2026-03-08

·

Updated

2026-04-23

·

CVE-2026-3787

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UltraVNC version 1.6.4.0
Description A weakness exists in UltraVNC 1.6.4.0 on Windows. The issue affects an unknown function within the cryptbase.dll library of the Windows Service component, leading to an uncontrolled search path. Local access is required for exploitation, and the exploitability is considered difficult due to the high complexity involved. The vendor was contacted regarding this disclosure but did not provide a response.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Windows Service component to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-3787

Affected Products

Ultravnc
Windows