๐Ÿ” CVE Alert

CVE-2026-107614

MEDIUM 6.1

Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.

CWE CWE-191 CWE-125
Vendor glavsoft
Product tightvnc
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for glavsoft tightvnc

Be the first to know when new medium vulnerabilities affecting glavsoft tightvnc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GlavSoft / TightVNC
0 < 2.8.88

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sourceforge.net: https://sourceforge.net/p/vnc-tight/bugs/1661/ tightvnc.com: https://www.tightvnc.com/whatsnew.php

Credits

Arjun Basnet from Securin