What the vulnerability does

01Description

UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.

Key dates

02Disclosure timeline

March 9, 2019 CVE published
September 17, 2024 Record updated