Incorrect Permission Assignment in TightVNC Server for Windows
CVE-2026-107612
7.8HIGH
What is CVE-2026-107612?
A vulnerability in TightVNC Server for Windows allows local authenticated users to exploit incorrect permission assignments, enabling them to read or overwrite inter-process communication handles. This occurred due to a named shared memory segment being created with a NULL DACL, making it accessible for low-privileged processes. The segment name is predictable based on time, allowing malicious users to tamper with IPC channels of a service running with elevated privileges. This can lead to potential privilege escalation, disclosure of sensitive session data, or even denial of service.
Affected Version(s)
TightVNC Windows 0 < 2.8.88
