Impact
The vulnerability arises from the TightVNC Server for Windows creating a world‑accessible named shared memory segment used to store IPC pipe HANDLE values with a NULL DACL. The segment’s name is based on a one‑second seeded srand(time(0)) value, can authenticate locally as a low‑privileged user can open this mapping and modify the IPC channel that connects the TightVNC service running as SYSTEM to its desktop server process. This allows the attacker to read session data, insert malicious data into the channel, or terminate the service, leading to potential privilege escalation, confidential data disclosure, or denial of service.
Affected Systems
Vendors affected are GlavSoft with the TightVNC Server product. The vulnerability applies to Windows builds of TightVNC prior to version 2.8.88. No specific build numbers are listed beyond the generic pre‑2.8.88 designation.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity vulnerability. The EPSS score is not available, so the current exploit probability cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The attack requires local authenticated access to a low‑privileged account, but the functionally predictable IPC name makes discovery relatively straightforward in an environment where the attacker can query or guess the name. Exploit conditions do not demand administrative privileges to launch the initial attack step; however, further steps rely on the service’s SYSTEM context. Because the vulnerability leverages a predictable resource name and an overly permissive ACL, security teams should treat it with urgency when a vulnerable tightVNC installation is in use.
OpenCVE Enrichment