vendor:
UltraVNC Viewer
by:
Pepelux
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: UltraVNC Viewer
Affected Version From: UltraVNC 1.0.8.2
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 and Windows XP SP3
2010
UltraVNC Arbitrary Code Execution Vulnerability
The vulnerability allows attackers to execute arbitrary code by enticing a legitimate user to open a file from a network share location that contains a specially crafted DLL file. The issue is present in UltraVNC version 1.0.8.2 and possibly other versions.
Mitigation:
No mitigation provided in the given text