Impact
The vulnerability is an out‑of‑bounds read in TightVNC Viewer’s ZRLE decoder. A malicious or compromised VNC server can send ZRLE‑encoded tiles with palette indices that exceed the declared palette size. The readPaletteRleTile() and readPackedPaletteTile() functions use the attacker‑supplied index without bounds checking, causing the viewer to copy data from beyond the palette allocation into the framebuffer. This can lead to a display corruption or a crash, resulting in a denial of service or accidental disclosure of heap data. The weakness is identified as CWE‑125.
Affected Systems
The issue affects GlavSoft TightVNC Viewer for Windows versions prior to 2.8.88. Those installations that rely on the ZRLE compression algorithm are vulnerable. The offending code is present only in the Windows build, meaning that Linux or Mac clients are not impacted.
Risk and Exploitability
The CVSS base score for this flaw is 7.1, classifying it as a high‑severity vulnerability. The exploit probability is unknown because EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector described in the advisory requires an attacker who can control the VNC server that a victim connects to; by sending crafted ZRLE tiles, the attacker can trigger the out‑of‑bounds read, causing a crash or memory leakage. Since the viewer must download the data from the server, the risk is mitigated only by preventing connection to untrusted hosts or by patching the software.
OpenCVE Enrichment