CVE-2019-8277

HIGH

UltraVNC < 1.2.2.3 - Memory Leak and Information Disclosure via VNC Server

Title source: llm
STIX 2.1

Description

UltraVNC revision 1211 contains multiple memory leaks (CWE-665) in VNC server code, which allows an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.

References (6)

Core 6
Core References
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-20-161-06
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-11

Scores

CVSS v3 7.5
EPSS 0.0082
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-665
Status published
Products (4)
siemens/sinumerik_access_mymachine\/p2p < 4.8
siemens/sinumerik_pcu_base_win10_software\/ipc < 14.00
siemens/sinumerik_pcu_base_win7_software\/ipc < 12.01
uvnc/ultravnc < 1.2.2.3
Published Mar 08, 2019
Tracked Since Feb 18, 2026