An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Advisories

No advisories yet.

Fixes

Solution

Upgrade TightVNC for Windows to version 2.8.88 or later.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Title Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read
Weaknesses CWE-125
CWE-191
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:01:01.624Z

Reserved: 2026-10-08T13:23:07.677Z

Link: CVE-2026-107614

cve-icon Vulnrichment

Updated: 2026-10-08T14:00:55.983Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:50.163

Modified: 2026-10-08T15:17:45.787

Link: CVE-2026-107614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses