CVE-2019-8275
CRITICALUltraVNC < 1.2.2.3 - Remote Out-of-Bounds Read via Improper Null Termination
Title source: llmDescription
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
References (6)
Core 6
Core References
Third Party Advisory x_refsource_misc
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19-022-ultravnc-improper-null-termination/
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-20-161-06
Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-940818.pdf
Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-286838.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-11
Scores
CVSS v3
9.8
EPSS
0.0433
EPSS Percentile
89.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-170
Status
published
Products (4)
siemens/sinumerik_access_mymachine\/p2p
< 4.8
siemens/sinumerik_pcu_base_win10_software\/ipc
< 14.00
siemens/sinumerik_pcu_base_win7_software\/ipc
< 12.01
uvnc/ultravnc
< 1.2.2.3
Published
Mar 08, 2019
Tracked Since
Feb 18, 2026