Uncontrolled Search Path Vulnerability in GlavSoft TightVNC Server for Windows
CVE-2026-107615

7.8HIGH

Key Information:

Vendor

Glavsoft

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107615?

The GlavSoft TightVNC Server for Windows prior to version 2.8.88 contains an uncontrolled search path element vulnerability. This allows a local authenticated user to execute arbitrary code with SYSTEM privileges. The vulnerability arises when the DynamicLibrary::init() function loads 'screenhooks32.dll' and 'screenhooks64.dll' without appropriate LOAD_LIBRARY_SEARCH flags. As a result, if an attacker places a malicious DLL in a writable directory preceding the legitimate DLL in the search order, it can be executed, potentially compromising the affected system.

Affected Version(s)

TightVNC Windows 0 < 2.8.88

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.