CVE-2026-107611: Out-of-bounds read in TightVNC Viewer ZRLE palette decoding

Published Oct 8, 2026
·
Updated

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.

Affected Software

1 affected component
GlavSoft TightVNC Viewer for Windows<2.8.88

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GlavSoft TightVNC Viewer for Windows to a version that resolves this vulnerability.

    Fixed in 2.8.88

Event History

Oct 8, 2026
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

GlavSoft TightVNC Viewer for Windows versions before 2.8.88 are affected when they connect to a malicious or compromised VNC server that sends crafted ZRLE-encoded tiles.

2

What must an attacker control to trigger the vulnerability?

The attacker needs to operate or compromise a VNC server that the user connects to, and send ZRLE tiles with palette indices larger than the declared palette size. No attacker privileges on the viewer system are required, but user interaction is required to connect the viewer to that server.

3

What are the observable effects of exploitation?

Invalid palette lookups can copy out-of-bounds heap data into the framebuffer, causing a garbled display, or fault during the read and terminate the TightVNC Viewer process. The reported impact is limited confidentiality impact and high availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203