CVE-2019-8272

CRITICAL

UltraVNC < 1.2.2.3 - Remote Code Execution via Off-by-one Error

Title source: llm
STIX 2.1

Description

UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-20-161-06

Scores

CVSS v3 9.8
EPSS 0.0392
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-193
Status published
Products (4)
siemens/sinumerik_access_mymachine\/p2p < 4.8
siemens/sinumerik_pcu_base_win10_software\/ipc < 14.00
siemens/sinumerik_pcu_base_win7_software\/ipc < 12.01
uvnc/ultravnc < 1.2.2.3
Published Mar 08, 2019
Tracked Since Feb 18, 2026