Executive brief
UltraVNC, a popular remote desktop tool used for technical support and remote server management, contains a security weakness in its legacy login system. An attacker who can monitor network traffic between a user and the server can quickly crack the encryption used during login. This allows the attacker to steal usernames and passwords, potentially leading to unauthorized access to the remote computer and sensitive data.
Technical details
UltraVNC (through version 1.8.2.2) implements the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth) using weak cryptographic primitives. Specifically, the Diffie-Hellman (DH) key exchange in rfb/dh.cpp is restricted to a 64-bit prime size (DH_MAX_BITS), which is vulnerable to Pollard's rho algorithm in under one second. Furthermore, the private exponent is generated using a weak PRNG seeded by time(NULL), resulting in only ~31 bits of entropy. A passive network observer or man-in-the-middle attacker can recover the private exponent and shared key to decrypt the encapsulated credentials. This vulnerability does not affect the more modern MS-Logon III scheme.
Affected products
- uvnc UltraVNC through 1.8.2.2
Timeline
- 2026-07-01: advisory: NVD publication date