Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade TightVNC for Windows to version 2.8.88 or later.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition(). | |
| Title | NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initialization | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:01:33.803Z
Reserved: 2026-10-08T13:23:07.677Z
Link: CVE-2026-107613
Updated: 2026-10-08T14:01:26.950Z
Status : Received
Published: 2026-10-08T14:16:50.020
Modified: 2026-10-08T15:17:45.673
Link: CVE-2026-107613
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:15:14Z