CVE-2026-107614: Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GlavSoft TightVNC Server for Windowsto a version that resolves this vulnerability.Fixed in 2.8.88
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a local authenticated user on a Windows system running the affected TightVNC Server. The issue is triggered through the DXGI capture path.
What cursor conditions trigger the vulnerable processing?
A cursor shape with a width or height of zero can cause the underflow. A monochrome cursor with height 1 can also reach the condition because getCursorHeight() halves the height in place.
What is the practical impact?
An attacker can crash the TightVNC Server and may be able to read out-of-bounds memory. The wrapped loop bound can lead to an access roughly 4 GB beyond the 64 KB cursor buffer.
Which versions are affected?
GlavSoft TightVNC Server for Windows versions before 2.8.88 are affected.