vendor:
UltraVNC Launcher
by:
chuyreds
7.8
CVSS
HIGH
Local
20
CWE
Product Name: UltraVNC Launcher
Affected Version From: 1.2.4.0
Affected Version To: 1.2.4.0
Patch Exists: YES
Related CWE: N/A
CPE: a:uvnc:ultravnc:1.2.4.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
UltraVNC Launcher 1.2.4.0 – ‘Password’ Denial of Service (PoC)
UltraVNC Launcher 1.2.4.0 is prone to a denial-of-service vulnerability when a maliciously crafted 'Password' is supplied. An attacker can exploit this vulnerability to crash the application, denying service to legitimate users.
Mitigation:
Upgrade to the latest version of UltraVNC Launcher 1.2.4.0