CVE-2026-107611: Out-of-bounds read in TightVNC Viewer ZRLE palette decoding
An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GlavSoft TightVNC Viewer for Windowsto a version that resolves this vulnerability.Fixed in 2.8.88
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
GlavSoft TightVNC Viewer for Windows versions before 2.8.88 are affected when they connect to a malicious or compromised VNC server that sends crafted ZRLE-encoded tiles.
What must an attacker control to trigger the vulnerability?
The attacker needs to operate or compromise a VNC server that the user connects to, and send ZRLE tiles with palette indices larger than the declared palette size. No attacker privileges on the viewer system are required, but user interaction is required to connect the viewer to that server.
What are the observable effects of exploitation?
Invalid palette lookups can copy out-of-bounds heap data into the framebuffer, causing a garbled display, or fault during the read and terminate the TightVNC Viewer process. The reported impact is limited confidentiality impact and high availability impact.