Executive brief
UltraVNC is a remote desktop tool used to control computers over a network. A security flaw in the viewer component allows a malicious server or a man-in-the-middle attacker to crash the software or potentially take control of the user's computer when they attempt to connect. This could lead to unauthorized access to the user's system and data without requiring a successful login.
Technical details
An integer overflow exists in vncviewer/ClientConnection.cpp where a 4-byte network-supplied 'reasonLen' field is incremented by 1 before being passed to CheckBufferSize(). If an attacker provides a value of 0xFFFFFFFF, the addition overflows to 0, causing the application to allocate a small default buffer (256 bytes). A subsequent ReadString call then attempts to read the full 4 GiB of data into this undersized heap buffer. This vulnerability is reachable via rfbConnFailed and rfbVncAuthFailed message types during the handshake phase, requiring no authentication. Successful exploitation could allow for remote code execution (RCE) with the privileges of the user running the VNC viewer.
Affected products
- uvnc UltraVNC through 1.8.2.2
Timeline
- 2026-07-01: advisory: NVD publication date