GlavSoft TightVNC Server for Windows 版本低于 2.8.88 的权限分配错误漏洞,允许本地已认证用户读取或覆盖 TightVNC 服务与其桌面服务器进程之间使用的进程间通信(IPC)句柄。承载管道句柄值的命名共享内存段位于 Global\ 命名空间,其创建时使用了 NULL DACL( discretionary access control list,自主访问控制列表),且该名称基于以时间为种子的 srand(time(0)) 生成值,具有可预测性,精度可达秒级。低权限的本地进
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107615 | 7.8 HIGH | DLL search order hijacking via screenhooks libraries in TightVNC Server |
| CVE-2026-107611 | 7.1 HIGH | Out-of-bounds read in TightVNC Viewer ZRLE palette decoding |
| CVE-2026-107614 | 6.1 MEDIUM | Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read |
| CVE-2026-107613 | 5.9 MEDIUM | NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initiali |
No comments yet