CVE-2026-4962: UltraVNC Service version.dll uncontrolled search path
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs to be approached locally. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4962?
CVE-2026-4962 has been classified with a medium severity rating, indicating potential risk if exploited.
How do I fix CVE-2026-4962?
To mitigate CVE-2026-4962, upgrade to the latest version of UltraVNC beyond 1.6.4.0.
What causes CVE-2026-4962?
CVE-2026-4962 is caused by an uncontrolled search path in the version.dll of the UltraVNC Service.
Who is affected by CVE-2026-4962?
CVE-2026-4962 affects all versions of UltraVNC Service up to 1.6.4.0.
Can CVE-2026-4962 be exploited remotely?
Yes, CVE-2026-4962 can potentially be exploited remotely if the affected UltraVNC Service is exposed to the internet.