GlavSoft TightVNC Server for Windows 在 2.8.88 版本之前的 Win8ScreenDriver 组件中存在空指针解引用漏洞,攻击者可利用该漏洞导致服务器崩溃,从而引发拒绝服务(DoS)攻击。当在 applyNewScreenProperties() 函数中重新初始化 DXGI 桌面复制驱动失败时(例如在 GPU 重置、显示器热插拔或会话更改之后),m_drvImpl 会被置为 NULL,随后在未进行检查的情况下,executeDetection()、getScreenBuf
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107612 | 7.8 HIGH | World-accessible IPC shared memory with predictable name in TightVNC Server |
| CVE-2026-107615 | 7.8 HIGH | DLL search order hijacking via screenhooks libraries in TightVNC Server |
| CVE-2026-107611 | 7.1 HIGH | Out-of-bounds read in TightVNC Viewer ZRLE palette decoding |
| CVE-2026-107614 | 6.1 MEDIUM | Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read |
No comments yet