PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107611 GlavSoft CVE debrief

A vulnerability in TightVNC Viewer for Windows before 2.8.88 allows a malicious VNC server to crash the viewer by sending specially crafted ZRLE-encoded tiles. The vulnerability is due to an out-of-bounds read in the ZRLE decoder, which can lead to the viewer reading heap memory beyond the palette allocation. This can cause the viewer to crash or display garbled content. Defenders should be aware of the potential impact on their systems and take steps to mitigate the vulnerability. The vulnerability is caused by the readerPaletteRleTile() and readPackedPaletteTile() functions using the attacker-supplied index to look up colours without validating it against the palette size.

Vendor
GlavSoft
Product
TightVNC
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for managing and securing TightVNC Viewer for Windows installations should prioritize patching to version 2.8.88 or later to prevent potential crashes. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the security and stability of their systems.

Why it matters

Defenders should prioritize patching TightVNC Viewer for Windows to version 2.8.88 or later to prevent potential crashes due to an out-of-bounds read vulnerability in the ZRLE decoder.

  • Potential crashes of the TightVNC Viewer
  • Garbled display or read faults due to out-of-bounds heap data

Technical summary

The vulnerability is due to an out-of-bounds read in the ZRLE decoder of TightVNC Viewer for Windows before 2.8.88. A malicious VNC server can send ZRLE-encoded tiles with palette indices that exceed the declared palette size, causing the viewer to read heap memory beyond the palette allocation and crash. The vulnerability is caused by the readerPaletteRleTile() and readPackedPaletteTile() functions using the attacker-supplied index to look up colours without validating it against the palette size. This can lead to the viewer crashing or displaying garbled content.

Defensive priority

Defenders should prioritize patching TightVNC Viewer for Windows to version 2.8.88 or later to prevent potential crashes.

Recommended defensive actions

  • Patch TightVNC Viewer for Windows to version 2.8.88 or later
  • Restrict access to the TightVNC Viewer to trusted VNC servers only
  • Monitor for potential crashes or anomalies in the TightVNC Viewer
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is described in the CVE record and the source item from the CVE Program. The affected version is TightVNC Viewer for Windows before 2.8.88. The CVE record was published on 2026-10-08T13:39:48.883Z and has not been modified since then. Additional information can be found in the official CVE Program record and the NIST NVD detail page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107611 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107611

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107611 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107611

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Out-of-bounds read in TightVNC Viewer ZRLE palette decoding

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107611.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://sourceforge.net/p/vnc-tight/bugs/1657/

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://www.tightvnc.com/whatsnew.php

    Supplemental source - release-notes, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.