PatchSiren cyber security CVE debrief
CVE-2026-107614 GlavSoft CVE debrief
A local authenticated user can crash TightVNC Server and potentially read out-of-bounds memory by processing a cursor shape with a width or height of zero. This vulnerability, tracked as CVE-2026-107614, affects GlavSoft TightVNC Server for Windows versions before 2.8.88. The integer underflow in WinCursorShapeUtils::trimTransparent() allows an attacker to cause a cursor shape with a width or height of zero to be processed on the DXGI capture path, leading to a potential out-of-bounds memory read.
- Vendor
- GlavSoft
- Product
- TightVNC
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for managing and securing TightVNC Server installations should assess their exposure and take necessary actions to mitigate the vulnerability.
Why it matters
The integer underflow vulnerability in TightVNC Server can be exploited by a local authenticated user to crash the server and potentially read out-of-bounds memory. System administrators and security teams should assess their exposure and take necessary actions to mitigate the vulnerability.
- A local authenticated user can crash the TightVNC Server
- A local authenticated user can potentially read out-of-bounds memory
- Verify the version of TightVNC Server and update to 2.8.88 or later if necessary
- Restrict access to the TightVNC Server to authorized users only
Technical summary
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Defensive priority
Medium-priority defensive actions are recommended to address the integer underflow vulnerability in TightVNC Server.
Recommended defensive actions
- Update TightVNC Server to version 2.8.88 or later
- Restrict access to the TightVNC Server to authorized users only
- Monitor for suspicious activity on the system
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE Program record and NVD vulnerability detail provide information on the integer underflow vulnerability in TightVNC Server. The source item and supplemental sources offer additional context. The vulnerability is caused by an integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88. A local authenticated user can exploit this vulnerability by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0x
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107614 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107614
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107614 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107614
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Integer underflow in TightVNC Server cursor shape trimming leads to out-of-bounds read
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107614.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://sourceforge.net/p/vnc-tight/bugs/1661/
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://www.tightvnc.com/whatsnew.php
Supplemental source - release-notes, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.