CVE-2023-27830: Critical severity tightvnc vulnerability
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the TightVNC vulnerability?
The vulnerability ID of the TightVNC vulnerability is CVE-2023-27830.
What is the severity rating of CVE-2023-27830?
CVE-2023-27830 has a severity rating of critical.
How can an attacker exploit CVE-2023-27830?
An attacker can exploit CVE-2023-27830 by replacing legitimate files with crafted files during a file transfer, allowing them to escalate privileges on the host operating system.
Which version of TightVNC is affected by CVE-2023-27830?
TightVNC versions up to and excluding 2.8.75 are affected by CVE-2023-27830.
Are there any references available for more information about CVE-2023-27830?
Yes, you can find more information about CVE-2023-27830 at the following links: [Link 1](https://medium.com/nestedif/vulnerability-disclosure-privilege-escalation-tightvnc-8165208cce), [Link 2](https://www.tightvnc.com/news.php), [Link 3](https://www.tightvnc.com/whatsnew.php).