CVE-2026-107611
Received Received - Intake

Out-of-Bounds Read in TightVNC Viewer for Windows

Vulnerability report for CVE-2026-107611, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GlavSoft TightVNC 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read flaw in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows versions before 2.8.88. A malicious or compromised VNC server can exploit this by sending specially crafted ZRLE-encoded tiles. The viewer's functions readPaletteRleTile() and readPackedPaletteTile() fail to validate palette indices against the declared palette size, causing the viewer to read heap memory beyond the allocated palette. This can lead to a crash or display corruption as out-of-bounds data is copied into the framebuffer.

Detection Guidance

This vulnerability can be detected by checking the version of TightVNC Viewer installed on your system. If you are using a version before 2.8.88, your system is vulnerable. Commands to check the version include running 'tightvncviewer -version' on Windows or checking the installed program details in the system settings.

Impact Analysis

If you use a vulnerable version of TightVNC Viewer, a malicious VNC server could crash your viewer application or display garbled graphics. While it does not directly allow code execution, the crash could disrupt your work and potentially expose sensitive information through memory leakage. The impact is limited to the viewer process and does not affect the VNC server itself.

Compliance Impact

This vulnerability may indirectly affect compliance by increasing the risk of data exposure or service disruption if the viewer crashes or displays incorrect data. GDPR and HIPAA require protecting sensitive data and ensuring system availability; a crash or memory leak could violate these principles. However, the vulnerability itself does not directly lead to unauthorized data access unless combined with other exploits.

Mitigation Strategies

Immediately update TightVNC Viewer to version 2.8.88 or later. If updating is not possible, consider discontinuing use of the vulnerable version until patched. Ensure your VNC server is from a trusted source to prevent malicious exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107611. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart