Description
An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Out‑of‑bounds memory read leading to client crash or possible data leakage
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in TightVNC Viewer’s ZRLE decoder. A malicious or compromised VNC server can send ZRLE‑encoded tiles with palette indices that exceed the declared palette size. The readPaletteRleTile() and readPackedPaletteTile() functions use the attacker‑supplied index without bounds checking, causing the viewer to copy data from beyond the palette allocation into the framebuffer. This can lead to a display corruption or a crash, resulting in a denial of service or accidental disclosure of heap data. The weakness is identified as CWE‑125.

Affected Systems

The issue affects GlavSoft TightVNC Viewer for Windows versions prior to 2.8.88. Those installations that rely on the ZRLE compression algorithm are vulnerable. The offending code is present only in the Windows build, meaning that Linux or Mac clients are not impacted.

Risk and Exploitability

The CVSS base score for this flaw is 7.1, classifying it as a high‑severity vulnerability. The exploit probability is unknown because EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector described in the advisory requires an attacker who can control the VNC server that a victim connects to; by sending crafted ZRLE tiles, the attacker can trigger the out‑of‑bounds read, causing a crash or memory leakage. Since the viewer must download the data from the server, the risk is mitigated only by preventing connection to untrusted hosts or by patching the software.

Generated by OpenCVE AI on October 8, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Upgrade TightVNC for Windows to version 2.8.88 or later.


Vendor Workaround

Connect only to trusted VNC servers until the viewer is upgraded.


OpenCVE Recommended Actions

  • Upgrade TightVNC for Windows to version 2.8.88 or later.
  • If an upgrade cannot be performed immediately, connect only to trusted VNC servers and avoid unknown remote hosts until the viewer is patched.
  • Block or filter VNC traffic from sources that are not explicitly approved by using firewall rules or network segmentation, reducing the likelihood that an attacker can reach the vulnerable client.

Generated by OpenCVE AI on October 8, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.
Title Out-of-bounds read in TightVNC Viewer ZRLE palette decoding
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:03:01.404Z

Reserved: 2026-10-08T13:23:07.677Z

Link: CVE-2026-107611

cve-icon Vulnrichment

Updated: 2026-10-08T14:02:57.754Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:49.727

Modified: 2026-10-08T15:17:45.440

Link: CVE-2026-107611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:18Z

Weaknesses