Impact
Integer underflow in TightVNC Server’s WinCursorShapeUtils::trimTransparent() causes a local authenticated Windows user to crash the server and potentially read out‑of‑bounds memory. A cursor shape with zero width or height triggers a loop bound that underflows, leading to access of memory approximately 4 GB beyond the 64 KB cursor buffer and a monochrome cursor height being set to zero. The flaw can result in a denial‑of‑service or unintended disclosure of memory content.
Affected Systems
The vulnerability affects GlavSoft TightVNC Server for Windows versions prior to 2.8.88. Users running any earlier build of the Windows tight VNC server component are susceptible when processing cursor shapes with zero dimensions on the DXGI capture path.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity, and the EPSS score is not available. The flaw requires local authenticated access; it is not remotely exploitable. The lack of a KEV listing suggests no publicly known exploitation, but the possibility of a crash or memory read remains a concern for systems relying on tight VNC for remote control. Consequently, the risk is moderate but can impact availability or lead to accidental information leakage in environments where local users have rights to start the TightVNC service.
OpenCVE Enrichment