UltraVNC 1199 Client CoRRE Decoder Out-of-Bounds memory corruption

A vulnerability has been found in UltraVNC 1199 and classified as critical. Affected by this vulnerability is a functionality of the component Client CoRRE Decoder. The manipulation with an unknown input leads to a memory corruption vulnerability (Out-of-Bounds). The CWE definition for the vulnerability is CWE-119. As an impact it is known to affect confidentiality, integrity, and availability.

The weakness was shared 03/05/2019. This vulnerability is known as CVE-2019-8261 since 02/12/2019. The attack can be launched remotely. The technical details are unknown and an exploit is not publicly available. The pricing for an exploit might be around USD $0-$5k at the moment (estimation calculated on 03/06/2019).

Upgrading to version 1200 eliminates this vulnerability.

The issues 131356, 131357, 131358 and 131360 are related to this entry.



Class: Memory corruption / Out-of-Bounds (CWE-119)
Local: No
Remote: Yes

Recommended: Upgrade
Upgrade: UltraVNC 1200


02/12/2019 CVE assigned
03/05/2019 Advisory disclosed
03/06/2019 VulDB entry created
03/06/2019 VulDB last update


CVE: CVE-2019-8261 (🔒)
Created: 03/06/2019 08:44 AM
