Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade TightVNC for Windows to version 2.8.88 or later.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place. | |
| Title | Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read | |
| Weaknesses | CWE-125 CWE-191 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:01:01.624Z
Reserved: 2026-10-08T13:23:07.677Z
Link: CVE-2026-107614
Updated: 2026-10-08T14:00:55.983Z
Status : Received
Published: 2026-10-08T14:16:50.163
Modified: 2026-10-08T15:17:45.787
Link: CVE-2026-107614
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:15:14Z