No advisories yet.
Solution
Upgrade TightVNC for Windows to version 2.8.88 or later.
Workaround
Connect only to trusted VNC servers until the viewer is upgraded.
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glavsoft
Glavsoft tightvnc |
|
| Vendors & Products |
Glavsoft
Glavsoft tightvnc |
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer. | |
| Title | Out-of-bounds read in TightVNC Viewer ZRLE palette decoding | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:03:01.404Z
Reserved: 2026-10-08T13:23:07.677Z
Link: CVE-2026-107611
Updated: 2026-10-08T14:02:57.754Z
Status : Awaiting Analysis
Published: 2026-10-08T14:16:49.727
Modified: 2026-10-08T21:10:00.133
Link: CVE-2026-107611
No data.
OpenCVE Enrichment
Updated: 2026-10-09T08:05:11Z