vendor:
UltraVNC
by:
Victor Mondragón
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: UltraVNC
Affected Version From: 1.2.2.4
Affected Version To: 1.2.2.4
Patch Exists: No
Related CWE: N/A
CPE: a:uvnc:ultravnc:1.2.2.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64 Service Pack 1
2019
UltraVNC Launcher 1.2.2.4 – Denial of Service (PoC)
UltraVNC Launcher 1.2.2.4 is vulnerable to a denial of service attack when a maliciously crafted string is pasted into the 'Path vncviewer.exe' field. This causes the application to crash when the 'OK' button is clicked.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in the application.