nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42049 CVE-2024-42049
CRITICAL
TightVNC 2.8.83 - Control Pipe Manipulation
Record summary
CVE-2024-42049 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tightvncBrowse tightvnc / tightvncDefault status: unknown | CVE List | Before 2.8.84 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBTightVNC 2.8.83 - Control Pipe ManipulationExploitDB exploitby Ionut ZevedeiNot analyzed1 file
Repository PoCs
GitHubzeved/CVE-2024-42049-PoCRepository PoCby zevedStars: 0Not analyzed11 files
References
3sourceforge.net
https://sourceforge.net/p/vnc-tight/bugs/1629 tightvnc.com
https://www.tightvnc.com/whatsnew.php