CVE-2020-37134: UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service
Published Feb 5, 2026
·Updated
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.
Affected Software
1 affected component
UltraVNC UltraVNC Viewer
Event History
Feb 5, 2026
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-37134?
CVE-2020-37134 is rated as a high severity denial of service vulnerability affecting UltraVNC Viewer 1.2.4.0.
2
How do I fix CVE-2020-37134?
To mitigate CVE-2020-37134, upgrade to a patched version of UltraVNC Viewer where the vulnerability is addressed.
3
What types of attacks are possible with CVE-2020-37134?
CVE-2020-37134 allows attackers to crash the UltraVNC Viewer application by sending a malformed payload.
4
Who is affected by CVE-2020-37134?
Users of UltraVNC Viewer version 1.2.4.0 are affected by CVE-2020-37134.
5
When was CVE-2020-37134 discovered?
CVE-2020-37134 was disclosed in December 2020.