CVE-2020-37132: UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37132?
CVE-2020-37132 is classified as a denial of service vulnerability that allows local attackers to crash the UltraVNC Launcher application.
How do I fix CVE-2020-37132?
To mitigate CVE-2020-37132, users should avoid entering overly long strings in the password field and consider updating to a patched version of UltraVNC Launcher if available.
Who is affected by CVE-2020-37132?
CVE-2020-37132 affects users of UltraVNC Launcher version 1.2.4.0.
What type of attack is CVE-2020-37132 associated with?
CVE-2020-37132 is associated with a local denial of service attack caused by an overly long password string.
Can CVE-2020-37132 be exploited remotely?
No, CVE-2020-37132 can only be exploited by local attackers with access to the application's password field.