UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSiemens Sinumerik Access Mymachine\/p2p
APPSiemens< 4.8Siemens Sinumerik Pcu Base Win10 Software\/ipc
APPSiemens< 14.00Siemens Sinumerik Pcu Base Win7 Software\/ipc
APPSiemens≤ 12.01Uvnc Ultravnc
APPUvnc< 1.2.2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2026-7840CRITICAL9.3PL ✓same product
UltraVNC Repeater: global buffer overflow w serwerze HTTP (RCE bez uwierzytelnienia)
CVE-2026-7839CRITICAL9.1PL ✓same product
UltraVNC Repeater — hardcoded domyślne hasło administratora HTTP
CVE-2019-8268CRITICAL9.8PL ✓same product
UltraVNC: wielokrotne podatności off-by-one umożliwiające RCE
CVE-2019-8265CRITICAL9.8PL ✓same product
UltraVNC – wielokrotne odczyty/zapisy poza buforem przez makro SETPIXELS
CVE-2019-8264CRITICAL9.8PL ✓same product
UltraVNC: podatność out-of-bounds w dekoderze Ultra2 klienta VNC (RCE)