PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107614 GlavSoft CVE debrief

A local authenticated user can crash TightVNC Server and potentially read out-of-bounds memory by processing a cursor shape with a width or height of zero. This vulnerability, tracked as CVE-2026-107614, affects GlavSoft TightVNC Server for Windows versions before 2.8.88. The integer underflow in WinCursorShapeUtils::trimTransparent() allows an attacker to cause a cursor shape with a width or height of zero to be processed on the DXGI capture path, leading to a potential out-of-bounds memory read.

Vendor
GlavSoft
Product
TightVNC
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

System administrators and security teams responsible for managing and securing TightVNC Server installations should assess their exposure and take necessary actions to mitigate the vulnerability.

Why it matters

The integer underflow vulnerability in TightVNC Server can be exploited by a local authenticated user to crash the server and potentially read out-of-bounds memory. System administrators and security teams should assess their exposure and take necessary actions to mitigate the vulnerability.

  • A local authenticated user can crash the TightVNC Server
  • A local authenticated user can potentially read out-of-bounds memory
  • Verify the version of TightVNC Server and update to 2.8.88 or later if necessary
  • Restrict access to the TightVNC Server to authorized users only

Technical summary

An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.

Defensive priority

Medium-priority defensive actions are recommended to address the integer underflow vulnerability in TightVNC Server.

Recommended defensive actions

  • Update TightVNC Server to version 2.8.88 or later
  • Restrict access to the TightVNC Server to authorized users only
  • Monitor for suspicious activity on the system
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE Program record and NVD vulnerability detail provide information on the integer underflow vulnerability in TightVNC Server. The source item and supplemental sources offer additional context. The vulnerability is caused by an integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88. A local authenticated user can exploit this vulnerability by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0x

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107614 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107614

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107614 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107614

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.