uvnc UltraVNC是uvnc个人开发者开源的一款Windows远程控制软件。 UltraVNC 1.8.2.2及之前版本存在信任管理问题漏洞,该漏洞源于HTTP管理服务器使用硬编码默认密码初始化,在首次运行时将字符串“adminadmi2”写入为管理员密码,且HTTP基本认证处理程序无速率限制或锁定机制,可导致远程攻击者使用已知默认凭据以管理员身份进行身份验证,从而完全控制中继器配置(包括允许/拒绝规则和会话可见性)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-7840 | 9.8 CRITICAL | UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE) |
| CVE-2026-7838 | 8.8 HIGH | UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason |
| CVE-2026-7831 | 7.5 HIGH | UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing |
| CVE-2026-7830 | 7.4 HIGH | UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential |
| CVE-2026-7829 | 7.2 HIGH | UltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token |
| CVE-2026-7828 | 5.3 MEDIUM | UltraVNC repeater integer overflow in win_log malloc leading to heap overflow |
| CVE-2026-44040 | 4.8 MEDIUM | UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge b |
| CVE-2026-44041 | 4.3 MEDIUM | UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated |
| CVE-2026-44042 | 3.7 LOW | UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check |
No comments yet