NULL Pointer Dereference in TightVNC Server Component by GlavSoft
CVE-2026-107613
5.9MEDIUM
What is CVE-2026-107613?
A vulnerability exists in the Win8ScreenDriver component of the GlavSoft TightVNC Server for Windows prior to version 2.8.88. The issue arises during the re-initialization of the DXGI Desktop Duplication driver within the applyNewScreenProperties() function, potentially following a GPU reset, display hot-plug, or session change. In situations where m_drvImpl remains NULL, several functions—including executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged(), and getCursorPosition()—attempt to dereference this NULL pointer, leading to a crash of the TightVNC Server and resulting in a denial of service.
Affected Version(s)
TightVNC Windows 0 < 2.8.88
