CVE-2019-25601: UltraVNC Launcher 1.2.2.4 Denial of Service Buffer Overflow
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25601?
CVE-2019-25601 is classified as a denial of service vulnerability.
How do I fix CVE-2019-25601?
To fix CVE-2019-25601, upgrade UltraVNC Launcher to a version that is not affected by this vulnerability.
What kind of attack does CVE-2019-25601 enable?
CVE-2019-25601 allows local attackers to crash the application by exploiting a buffer overflow.
Which software version is affected by CVE-2019-25601?
CVE-2019-25601 affects UltraVNC Launcher version 1.2.2.4.
Can CVE-2019-25601 be exploited remotely?
No, CVE-2019-25601 can only be exploited by local attackers due to the nature of the vulnerability.