Heap Buffer Overflow Vulnerability in UltraVNC Revision 1211: Potential Code Execution

Heap Buffer Overflow Vulnerability in UltraVNC Revision 1211: Potential Code Execution

CVE-2019-8274 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

Learn more about our Cis Benchmark Audit For Server Software.