CVE-2001-0167

ATT Winvnc < 3.3.3r7 - Buffer Overflow

Title source: rule

Description

Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16489
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/vnc/realvnc_client.rb

Scores

EPSS 0.6540
EPSS Percentile 98.5%

Details

Status published
Products (1)
att/winvnc < 3.3.3r7
Published May 03, 2001
Tracked Since Feb 18, 2026