Out-of-bounds Read Vulnerability in GlavSoft TightVNC Viewer for Windows
CVE-2026-107611

7.1HIGH

Key Information:

Vendor

Glavsoft

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107611?

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows allows malicious actors to exploit the viewer. By sending ZRLE-encoded tiles with palette indices that exceed the declared palette size, an attacker can manipulate the viewer's memory. The functions readPaletteRleTile() and readPackedPaletteTile() fail to validate the provided indices, leading to potential exposure of sensitive heap data and possible crashes of the viewer, resulting in a garbled display and an abrupt termination of the application.

Affected Version(s)

TightVNC Windows 0 < 2.8.88

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.