Impact
The vulnerability arises from an uncontrolled search path element in TightVNC Server for Windows before version 2.8.88. The server loads screenhooks32.dll or screenhooks64.dll using LoadLibrary with a bare file name and no LOAD_LIBRARY_SEARCH_* flags, so it follows the default DLL search order. An attacker who can write to a directory that appears earlier in the search order—such as the TightVNC installation directory with permissive ACLs—can place a malicious DLL. When the service loads the DLL, the code runs with SYSTEM privileges, giving the attacker arbitrary code execution on the host. This issue is a classic DLL hijacking scenario and is mapped to CWE‑427.
Affected Systems
Affected systems are machines running GlavSoft TightVNC Server for Windows versions prior to 2.8.88. Users with local authenticated access to the server can exploit the flaw. No specific sub-version details are listed beyond the stated version threshold. The recommended upgrade is to TightVNC 2.8.88 or newer, which replaces the vulnerable DLL loading logic.
Risk and Exploitability
The CVSS v3 score of 7.8 indicates a high severity, and the lack of EPSS data means the exploitation probability is uncertain; however, the vulnerability requires only local write access to a directory that appears early in the DLL search path, which is common on many installations. The KEV status indicates it is not listed in CISA KEV, but the high potential for local privilege escalation makes it a serious risk. The attack vector is local through DLL hijacking, and the exploit is straightforward for a user with write permissions to the relevant directories.
OpenCVE Enrichment