Description
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
chuyreds
References
www.exploit-db.com/exploits/48291 (ExploitDB-48291)
www.uvnc.com/ (UltraVNC Official Homepage)
www.vulncheck.com/...avnc-viewer-vncserver-denial-of-service (VulnCheck Advisory: UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service)