The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade vnc-serverUpgrade vnc | Dec 1, 2016 | Jan 16, 2009 |
| Gentoo Linux | — | Upgrade net-misc/vnc. | Oct 30, 2017 | Jan 16, 2009 |
| Oracle_linux | — | Upgrade vncUpgrade vnc-server | Oct 16, 2024 | Jan 16, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub