CVE-2019-8275: Critical severity ultravnc vulnerability
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-8275?
CVE-2019-8275 is classified as a high severity vulnerability due to the potential for attackers to exploit it remotely.
How do I fix CVE-2019-8275?
To fix CVE-2019-8275, update to UltraVNC revision 1212 or a later version.
What are the affected versions for CVE-2019-8275?
CVE-2019-8275 affects UltraVNC versions up to 1.2.2.3 and several Siemens products including various SIMATIC and SINAMICS systems.
Can CVE-2019-8275 be exploited remotely?
Yes, CVE-2019-8275 can be exploited remotely due to improper null termination vulnerabilities.
What type of vulnerability is CVE-2019-8275?
CVE-2019-8275 is characterized by multiple improper null termination vulnerabilities leading to out-of-bounds data access.