CVE-2019-8268: Critical severity ultravnc vulnerability
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8268?
CVE-2019-8268 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2019-8268?
To fix CVE-2019-8268, update UltraVNC to version 1.2.2.3 or later, and ensure all affected Siemens software is patched to the latest version.
What type of vulnerability is CVE-2019-8268?
CVE-2019-8268 is categorized as an off-by-one vulnerability affecting the VNC client code.
Can CVE-2019-8268 be exploited remotely?
Yes, CVE-2019-8268 can be exploited remotely through network connectivity.
Which software versions are affected by CVE-2019-8268?
CVE-2019-8268 affects specific versions of UltraVNC and several versions of Siemens Sinumerik software.