CVE-2026-107613
Received Received - Intake

NULL Pointer Dereference in TightVNC Server for Windows

Vulnerability report for CVE-2026-107613, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GlavSoft TightVNC 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL pointer dereference vulnerability in GlavSoft TightVNC Server for Windows before version 2.8.88. It occurs in the Win8ScreenDriver component when DXGI Desktop Duplication driver re-initialization fails. This leaves a pointer NULL, which is later used without checking in several functions, causing a crash.

Detection Guidance

This vulnerability may cause the TightVNC Server to crash unexpectedly. Monitor for server crashes or service failures, especially after GPU resets, display changes, or session switches. Check logs for NULL pointer dereference errors in Win8ScreenDriver.

Impact Analysis

An attacker could exploit this to crash the TightVNC server, resulting in a denial of service. This would prevent remote access to the affected system until the server is manually restarted.

Mitigation Strategies

Upgrade GlavSoft TightVNC Server for Windows to version 2.8.88 or later to address the NULL pointer dereference issue in Win8ScreenDriver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107613. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart