Description
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Published: 2026-10-08
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Out‑of‑bounds read and crash (Denial‑of‑Service)
Action: Immediate Patch
AI Analysis

Impact

Integer underflow in TightVNC Server’s WinCursorShapeUtils::trimTransparent() causes a local authenticated Windows user to crash the server and potentially read out‑of‑bounds memory. A cursor shape with zero width or height triggers a loop bound that underflows, leading to access of memory approximately 4 GB beyond the 64 KB cursor buffer and a monochrome cursor height being set to zero. The flaw can result in a denial‑of‑service or unintended disclosure of memory content.

Affected Systems

The vulnerability affects GlavSoft TightVNC Server for Windows versions prior to 2.8.88. Users running any earlier build of the Windows tight VNC server component are susceptible when processing cursor shapes with zero dimensions on the DXGI capture path.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity, and the EPSS score is not available. The flaw requires local authenticated access; it is not remotely exploitable. The lack of a KEV listing suggests no publicly known exploitation, but the possibility of a crash or memory read remains a concern for systems relying on tight VNC for remote control. Consequently, the risk is moderate but can impact availability or lead to accidental information leakage in environments where local users have rights to start the TightVNC service.

Generated by OpenCVE AI on October 8, 2026 at 16:07 UTC.

Remediation

Vendor Solution

Upgrade TightVNC for Windows to version 2.8.88 or later.


OpenCVE Recommended Actions

  • Upgrade TightVNC for Windows to version 2.8.88 or later.
  • If an upgrade cannot be performed immediately, limit the number of local accounts with permission to start or stop the TightVNC service and monitor such users for suspicious activity.
  • Run the TightVNC service under a least‑privilege user account and consider disabling cursor capture features if they are not required for remote sessions.

Generated by OpenCVE AI on October 8, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Title Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read
Weaknesses CWE-125
CWE-191
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:01:01.624Z

Reserved: 2026-10-08T13:23:07.677Z

Link: CVE-2026-107614

cve-icon Vulnrichment

Updated: 2026-10-08T14:00:55.983Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:50.163

Modified: 2026-10-08T15:17:45.787

Link: CVE-2026-107614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)