GlavSoft TightVNC Server for Windows 版本低于 2.8.88 中存在一个不受控的搜索路径元素漏洞,允许本地认证用户以 SYSTEM 权限执行任意代码。DynamicLibrary::init()(以及 ThemeLib)函数使用 LoadLibrary() 函数加载 screenhooks32.dll / screenhooks64.dll 时,仅使用了裸文件名,而未指定 LOAD_LIBRARY_SEARCH_* 标志。因此,TightVNC 服务遵循默认的 DLL 搜索顺序,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107612 | 7.8 HIGH | World-accessible IPC shared memory with predictable name in TightVNC Server |
| CVE-2026-107611 | 7.1 HIGH | Out-of-bounds read in TightVNC Viewer ZRLE palette decoding |
| CVE-2026-107614 | 6.1 MEDIUM | Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read |
| CVE-2026-107613 | 5.9 MEDIUM | NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initiali |
No comments yet