Integer Underflow in TightVNC Server for Windows Affects Cursor Functionality
CVE-2026-107614
6.1MEDIUM
What is CVE-2026-107614?
The TightVNC Server for Windows contains an integer underflow vulnerability in the WinCursorShapeUtils::trimTransparent() function. This issue arises when a local authenticated user manipulates cursor shape parameters, specifically by processing a cursor with a width or height of zero. This manipulation can lead to a server crash and potential out-of-bounds memory access, as the resulting computation refers to an invalid memory range. Specifically, the loop control improperly allows access to a region approximately 4 GB beyond a defined cursor buffer size, creating significant security risks for systems utilizing this software.
Affected Version(s)
TightVNC Windows 0 < 2.8.88
