Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade TightVNC for Windows to version 2.8.88 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place. | |
| Title | Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read | |
| Weaknesses | CWE-125 CWE-191 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:01:01.624Z
Reserved: 2026-10-08T13:23:07.677Z
Link: CVE-2026-107614
Updated: 2026-10-08T14:00:55.983Z
Status : Received
Published: 2026-10-08T14:16:50.163
Modified: 2026-10-08T15:17:45.787
Link: CVE-2026-107614
No data.
OpenCVE Enrichment
No data.