CVE-2001-0167
AT&T WinVNC < 3.3.3r7 - Remote Code Execution via Long rfbConnFailed Reason String
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2001-0167.
PoCs published by Metasploit, including Metasploit module exploits/windows/vnc/realvnc_client.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in RealVNC 3.3.7 (vncviewer.exe) by sending a maliciously crafted RFB protocol response to trigger remote code execution. The exploit targets specific return addresses for Windows 2000, XP, and 2003.
Description
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
Exploits (2)
This Metasploit module exploits a buffer overflow in RealVNC 3.3.7 (vncviewer.exe) by sending a maliciously crafted RFB protocol response to trigger remote code execution. The exploit targets specific return addresses for Windows 2000, XP, and 2003.
This Metasploit module exploits a buffer overflow in RealVNC 3.3.7 (vncviewer.exe) by sending a maliciously crafted RFB protocol response to trigger remote code execution. It includes target-specific return addresses for Windows 2000, XP, and 2003.