CVE-2026-107613: NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initialization
A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), mdrvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GlavSoft TightVNC Server for Windowsto a version that resolves this vulnerability.Fixed in 2.8.88
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
GlavSoft TightVNC Server for Windows versions before 2.8.88 are affected when using the Win8ScreenDriver component. The crash path occurs if DXGI Desktop Duplication driver re-initialization fails.
What conditions are needed to trigger the crash?
An attacker does not need privileges or user interaction, but exploitation has high attack complexity. A failed DXGI re-initialization is required, such as after a GPU reset, display hot-plug, or session change, after which subsequent screen-driver operations can dereference a NULL m_drvImpl pointer.
What is the impact if the issue is exploited?
The affected TightVNC Server process can crash, causing denial of service. The provided severity vector indicates no confidentiality or integrity impact.
How can I determine whether a system is affected?
Check whether the system runs GlavSoft TightVNC Server for Windows before version 2.8.88 and uses Win8ScreenDriver. Systems that experience TightVNC Server crashes following GPU resets, display changes, or session changes may be encountering this condition.