CVE-2019-25600: UltraVNC Viewer 1.2.2.4 Denial of Service via Buffer Overflow
UltraVNC Viewer 1.2.2.4 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized string to the VNC Server input field. Attackers can paste a malicious string containing 256 repeated characters into the VNC Server field and click Connect to trigger a buffer overflow that crashes the viewer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25600?
CVE-2019-25600 has a severity rating of medium due to its denial of service potential.
How do I fix CVE-2019-25600?
To fix CVE-2019-25600, upgrade UltraVNC Viewer to a version that is not vulnerable as specified by the vendor.
What type of vulnerability is CVE-2019-25600?
CVE-2019-25600 is a denial of service vulnerability caused by a buffer overflow.
What is affected by CVE-2019-25600?
CVE-2019-25600 affects UltraVNC Viewer version 1.2.2.4.
How can an attacker exploit CVE-2019-25600?
An attacker can exploit CVE-2019-25600 by supplying an oversized string to the VNC Server input field to crash the application.