UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.
References
Link | Resource |
---|---|
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19-008-ultravnc-heap-based-buffer-overflow/ | Third Party Advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf | Third Party Advisory |
https://www.us-cert.gov/ics/advisories/icsa-20-161-06 | Third Party Advisory US Government Resource |
https://cert-portal.siemens.com/productcert/pdf/ssa-940818.pdf | |
https://cert-portal.siemens.com/productcert/pdf/ssa-286838.pdf | |
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-11 |
Configurations
Information
Published : 2019-03-05 07:29
Updated : 2021-06-28 05:15
NVD link : CVE-2019-8262
Mitre link : CVE-2019-8262
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
siemens
- sinumerik_pcu_base_win10_software\/ipc
- sinumerik_access_mymachine\/p2p
- sinumerik_pcu_base_win7_software\/ipc
uvnc
- ultravnc