Uncontrolled Search Path Vulnerability in GlavSoft TightVNC Server for Windows
CVE-2026-107615
7.8HIGH
What is CVE-2026-107615?
The GlavSoft TightVNC Server for Windows prior to version 2.8.88 contains an uncontrolled search path element vulnerability. This allows a local authenticated user to execute arbitrary code with SYSTEM privileges. The vulnerability arises when the DynamicLibrary::init() function loads 'screenhooks32.dll' and 'screenhooks64.dll' without appropriate LOAD_LIBRARY_SEARCH flags. As a result, if an attacker places a malicious DLL in a writable directory preceding the legitimate DLL in the search order, it can be executed, potentially compromising the affected system.
Affected Version(s)
TightVNC Windows 0 < 2.8.88
