NULL Pointer Dereference in TightVNC Server Component by GlavSoft
CVE-2026-107613

5.9MEDIUM

Key Information:

Vendor

Glavsoft

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107613?

A vulnerability exists in the Win8ScreenDriver component of the GlavSoft TightVNC Server for Windows prior to version 2.8.88. The issue arises during the re-initialization of the DXGI Desktop Duplication driver within the applyNewScreenProperties() function, potentially following a GPU reset, display hot-plug, or session change. In situations where m_drvImpl remains NULL, several functions—including executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged(), and getCursorPosition()—attempt to dereference this NULL pointer, leading to a crash of the TightVNC Server and resulting in a denial of service.

Affected Version(s)

TightVNC Windows 0 < 2.8.88

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.