CVE-2026-44041: UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated

Published Jul 1, 2026
·
Updated

UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp:204, the vncWc2Mb() function passes a caller-supplied WCHAR pointer to wcslen() before any bounds check. If the caller provides a wide-character buffer that is not properly NUL-terminated, wcslen() reads past the end of the buffer until it encounters a NUL wchar, resulting in an out-of-bounds read. Under typical Win32 API usage this requires an abnormal caller contract. Impact is limited to a potential information disclosure from adjacent memory regions or a process crash (denial of service) if the over-read crosses a page boundary.

Affected Software

2 affected components
UltraVNC UltraVNC<=1.8.2.2
Uvnc Ultravnc<=1.8.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade UltraVNC to a version that resolves this vulnerability.

    Fixed in 1.8.2.2
  2. Compensating control

    Ensure callers provide properly NUL-terminated WCHAR buffers to vncWc2Mb() (rfb/dh.cpp:204) to avoid wcslen() over-reading past the buffer end.

Event History

Jul 1, 2026
CVE Published
via MITRE·03:33 AM
Data Sourced
via MITRE·03:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2026-44041?

CVE-2026-44041 is a vulnerability in UltraVNC versions up to 1.8.2.2 that allows for an out-of-bounds read due to a lack of validation in the vncWc2Mb() function.

2

What is the severity of CVE-2026-44041?

The severity of CVE-2026-44041 is medium, rated at 6.5 on the CVSS scale.

3

How do I fix CVE-2026-44041?

To fix CVE-2026-44041, upgrade to UltraVNC version that has addressed this vulnerability.

4

What impact does CVE-2026-44041 have on UltraVNC users?

CVE-2026-44041 can lead to potential information disclosure due to an out-of-bounds read when processing wide strings in UltraVNC.

5

Is CVE-2026-44041 exploitable remotely?

Yes, CVE-2026-44041 is exploitable remotely as it involves a caller-supplied WCHAR pointer in UltraVNC.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203