๐Ÿ” CVE Alert

CVE-2026-107613

MEDIUM 5.9

NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initialization

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().

CWE CWE-476
Vendor glavsoft
Product tightvnc
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for glavsoft tightvnc

Be the first to know when new medium vulnerabilities affecting glavsoft tightvnc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GlavSoft / TightVNC
0 < 2.8.88

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sourceforge.net: https://sourceforge.net/p/vnc-tight/bugs/1660/ tightvnc.com: https://www.tightvnc.com/whatsnew.php

Credits

Arjun Basnet from Securin