UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-286838.pdf | |
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf | Third Party Advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-940818.pdf | |
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19-008-ultravnc-heap-based-buffer-overflow/ | Third Party Advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-11 | |
https://www.us-cert.gov/ics/advisories/icsa-20-161-06 | Third Party Advisory US Government Resource |
Configurations
History
No history.
Information
Published : 2019-03-05 15:29
Updated : 2021-06-28 12:15
NVD link : CVE-2019-8262
Mitre link : CVE-2019-8262
CVE.ORG link : CVE-2019-8262
JSON object : View
Products Affected
siemens
- sinumerik_pcu_base_win7_software\/ipc
- sinumerik_access_mymachine\/p2p
- sinumerik_pcu_base_win10_software\/ipc
uvnc
- ultravnc