CVE-2019-8268
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.9%
exploitation probability
3.9%top 11% of all CVEs
observed exploitation
nono source reports it
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.
Affected products
Kaspersky Lab · UltraVNC