Description
Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity. A low-privileged local process can open the mapping and tamper with the IPC channel of a service running as SYSTEM, potentially leading to disclosure of session data, privilege escalation, or denial of service.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Data Disclosure via IPC Tampering
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the TightVNC Server for Windows creating a world‑accessible named shared memory segment used to store IPC pipe HANDLE values with a NULL DACL. The segment’s name is based on a one‑second seeded srand(time(0)) value, can authenticate locally as a low‑privileged user can open this mapping and modify the IPC channel that connects the TightVNC service running as SYSTEM to its desktop server process. This allows the attacker to read session data, insert malicious data into the channel, or terminate the service, leading to potential privilege escalation, confidential data disclosure, or denial of service.

Affected Systems

Vendors affected are GlavSoft with the TightVNC Server product. The vulnerability applies to Windows builds of TightVNC prior to version 2.8.88. No specific build numbers are listed beyond the generic pre‑2.8.88 designation.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity vulnerability. The EPSS score is not available, so the current exploit probability cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The attack requires local authenticated access to a low‑privileged account, but the functionally predictable IPC name makes discovery relatively straightforward in an environment where the attacker can query or guess the name. Exploit conditions do not demand administrative privileges to launch the initial attack step; however, further steps rely on the service’s SYSTEM context. Because the vulnerability leverages a predictable resource name and an overly permissive ACL, security teams should treat it with urgency when a vulnerable tightVNC installation is in use.

Generated by OpenCVE AI on October 8, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Upgrade TightVNC for Windows to version 2.8.88 or later.


OpenCVE Recommended Actions

  • Upgrade TightVNC for Windows to version 2.8.88 or later
  • Disable or remove the TightVNC service if the application is not required, to eliminate the attack surface
  • Consider restricting local user privileges or limiting access to the Global\\ namespace to prevent unauthorized memory mapping

Generated by OpenCVE AI on October 8, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity. A low-privileged local process can open the mapping and tamper with the IPC channel of a service running as SYSTEM, potentially leading to disclosure of session data, privilege escalation, or denial of service.
Title World-accessible IPC shared memory with predictable name in TightVNC Server
Weaknesses CWE-338
CWE-732
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:02:27.703Z

Reserved: 2026-10-08T13:23:07.677Z

Link: CVE-2026-107612

cve-icon Vulnrichment

Updated: 2026-10-08T14:01:55.171Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:49.877

Modified: 2026-10-08T15:17:45.557

Link: CVE-2026-107612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:18Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

  • CWE-732

    Incorrect Permission Assignment for Critical Resource