CVE-2026-107612
Received Received - Intake

Incorrect Permission Assignment in TightVNC Server for Windows

Vulnerability report for CVE-2026-107612, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity. A low-privileged local process can open the mapping and tamper with the IPC channel of a service running as SYSTEM, potentially leading to disclosure of session data, privilege escalation, or denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GlavSoft TightVNC 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect permission assignment in GlavSoft TightVNC Server for Windows before version 2.8.88. A local authenticated user can read or overwrite inter-process communication handles between the TightVNC service and its desktop server process due to a named shared memory segment created with a NULL DACL. The segment name is predictable, allowing low-privileged processes to tamper with the IPC channel of a SYSTEM service.

Detection Guidance

Check if TightVNC Server for Windows is installed and verify the version is 2.8.88 or later. Inspect running services for 'TightVNC Server' and review shared memory segments in the Global namespace for NULL DACL permissions. Use tools like Process Explorer to monitor IPC handles and named objects.

Impact Analysis

This vulnerability can lead to disclosure of session data, privilege escalation, or denial of service. An attacker could exploit it to gain higher privileges, access sensitive information, or disrupt the TightVNC service running as SYSTEM.

Mitigation Strategies

Update TightVNC Server to version 2.8.88 or later immediately. Restrict local user permissions to prevent unauthorized access to shared memory segments. Monitor for unusual IPC handle tampering or service behavior changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107612. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart