CVE-2019-8277: High severity ultravnc vulnerability
UltraVNC revision 1211 contains multiple memory leaks (CWE-665) in VNC server code, which allows an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-8277?
CVE-2019-8277 is classified as having a medium severity due to its information disclosure potential resulting from memory leaks.
How do I fix CVE-2019-8277?
To mitigate CVE-2019-8277, update affected products to the latest firmware or version that addresses this vulnerability.
Which products are affected by CVE-2019-8277?
CVE-2019-8277 affects multiple versions of UltraVNC and various Siemens products, including SINAMICS and SIMATIC series.
Can CVE-2019-8277 be exploited remotely?
Yes, CVE-2019-8277 may be exploited remotely due to memory leak issues in the VNC server code.
What are the potential impacts of CVE-2019-8277?
The potential impacts of CVE-2019-8277 include unauthorized access to sensitive information and the ability to bypass Address Space Layout Randomization (ASLR).