CVE-2019-8268
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of Clien
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
CRITICAL · CVSS 9.8
EPSS 0.01404
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules2
YARA rules0