UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSiemens Sinumerik Access Mymachine\/p2p
APPSiemens< 4.8Siemens Sinumerik Pcu Base Win10 Software\/ipc
APPSiemens< 14.00Siemens Sinumerik Pcu Base Win7 Software\/ipc
APPSiemens≤ 12.01Uvnc Ultravnc
APPUvnc< 1.2.2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
References
Related vulnerabilities
CVE-2026-7840CRITICAL9.3PL ✓same product
UltraVNC Repeater: global buffer overflow w serwerze HTTP (RCE bez uwierzytelnienia)
CVE-2026-7839CRITICAL9.1PL ✓same product
UltraVNC Repeater — hardcoded domyślne hasło administratora HTTP
CVE-2019-8271CRITICAL9.8PL ✓same product
UltraVNC: heap buffer overflow w obsłudze transferu plików (RCE)
CVE-2019-8265CRITICAL9.8PL ✓same product
UltraVNC – wielokrotne odczyty/zapisy poza buforem przez makro SETPIXELS
CVE-2019-8264CRITICAL9.8PL ✓same product
UltraVNC: podatność out-of-bounds w dekoderze Ultra2 klienta VNC (RCE)