CVE-2019-8262
Description
UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
5.4
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in UltraVNC (MSI) (x64) 1.2.2.2 | Windows |
| Multiple Vulnerabilities are affected in UltraVNC (MSI) 1.2.2.2 | Windows |
| Multiple Vulnerabilities are affected in UltraVNC (x64) 1.2.2.2 | Windows |
| Multiple Vulnerabilities are affected in UltraVNC (x86) 1.2.2.2 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-349101 | UltraVNC (x64) (1.6.4.0) |
| PATCH-349100 | UltraVNC (1.6.4.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234