CVE-2019-8265: Critical severity ultravnc vulnerability
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1208.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-8265?
CVE-2019-8265 has a high severity due to its potential for code execution via network connectivity.
How do I fix CVE-2019-8265?
To fix CVE-2019-8265, update affected software to the latest version as specified in the manufacturer's advisory.
Which products are affected by CVE-2019-8265?
CVE-2019-8265 affects multiple products, including UltraVNC versions up to 1.2.2.3 and various Siemens SIMATIC and SINAMICS devices.
Can CVE-2019-8265 be exploited remotely?
Yes, CVE-2019-8265 can potentially be exploited remotely due to its network connectivity vulnerabilities.
Is there a patch available for CVE-2019-8265?
Yes, patches are available for CVE-2019-8265 in the latest updates from affected software vendors.