Description
A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before version 2.8.88. An attacker can exploit a failure in DXGI Desktop Duplication driver re‑initialization, leaving an internal pointer null and forcing the server to dereference it, which crashes the VNC service and results in a denial of service.

Affected Systems

This issue affects all installations of TightVNC Server for Windows that are older than version 2.8.88, regardless of the operating system version, when the Win8ScreenDriver is used. Deployments that rely on hardware acceleration and may experience GPU resets, display hot‑plug events, or session changes are particularly vulnerable.

Risk and Exploitability

The CVSS score of 5.9 places the attack in the moderate range; no EPSS data is available and the vulnerability is not listed in KEV. The likely attack vector is through normal VNC client activity, where a malicious session can trigger the driver failure and cause the server to crash. An attacker with network access to the VNC port can repeatedly attempt this until the service is disrupted.

Generated by OpenCVE AI on October 8, 2026 at 16:08 UTC.

Remediation

Vendor Solution

Upgrade TightVNC for Windows to version 2.8.88 or later.


OpenCVE Recommended Actions

  • Upgrade TightVNC Server for Windows to version 2.8.88 or later.
  • If upgrading immediately is not possible, restrict VNC access to trusted IP ranges and monitor for repeated screen capture failures.
  • Configure a watchdog or Windows service restart policy to automatically restart the TightVNC service when it stops due to a crash.

Generated by OpenCVE AI on October 8, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().
Title NULL pointer dereference in TightVNC Server Win8ScreenDriver after failed DXGI re-initialization
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:01:33.803Z

Reserved: 2026-10-08T13:23:07.677Z

Link: CVE-2026-107613

cve-icon Vulnrichment

Updated: 2026-10-08T14:01:26.950Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:50.020

Modified: 2026-10-08T15:17:45.673

Link: CVE-2026-107613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses