在 GlavSoft TightVNC Server for Windows 2.8.88 之前的版本中,WinCursorShapeUtils::trimTransparent() 函数存在整数下溢漏洞。本地经过身份验证的用户可以通过触发对宽度或高度为零的光标形状在 DXGI 捕获路径上的处理,导致服务器崩溃,并可能越界读取内存。具体而言,循环边界表达式 width - 1 会发生回绕,变为 0xFFFFFFFF,从而在 64 KB 的光标缓冲区之后约 4 GB 的位置进行内存访问;此外,对于高度为 1 的单色光
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107612 | 7.8 HIGH | World-accessible IPC shared memory with predictable name in TightVNC Server |
| CVE-2026-107615 | 7.8 HIGH | DLL search order hijacking via screenhooks libraries in TightVNC Server |
| CVE-2026-107611 | 7.1 HIGH | Out-of-bounds read in TightVNC Viewer ZRLE palette decoding |
| CVE-2026-107613 | 5.9 MEDIUM | NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initiali |
No comments yet