Impact
The vulnerability is a NULL pointer dereference in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before version 2.8.88. An attacker can exploit a failure in DXGI Desktop Duplication driver re‑initialization, leaving an internal pointer null and forcing the server to dereference it, which crashes the VNC service and results in a denial of service.
Affected Systems
This issue affects all installations of TightVNC Server for Windows that are older than version 2.8.88, regardless of the operating system version, when the Win8ScreenDriver is used. Deployments that rely on hardware acceleration and may experience GPU resets, display hot‑plug events, or session changes are particularly vulnerable.
Risk and Exploitability
The CVSS score of 5.9 places the attack in the moderate range; no EPSS data is available and the vulnerability is not listed in KEV. The likely attack vector is through normal VNC client activity, where a malicious session can trigger the driver failure and cause the server to crash. An attacker with network access to the VNC port can repeatedly attempt this until the service is disrupted.
OpenCVE Enrichment