PatchSiren

GlavSoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GlavSoft CVE published 2026-10-08

CVE-2026-107615

A local authenticated user can exploit a DLL search order hijacking vulnerability in TightVNC Server for Windows before 2.8.88 to execute arbitrary code with SYSTEM privileges. This vulnerability allows for potential code execution with elevated privileges, posing a significant risk to systems and data accessed through TightVNC Server. System administrators should assess exposure and prioritize patching t [truncated]

MEDIUM GlavSoft CVE published 2026-10-08

CVE-2026-107614

A local authenticated user can crash TightVNC Server and potentially read out-of-bounds memory by processing a cursor shape with a width or height of zero. This vulnerability, tracked as CVE-2026-107614, affects GlavSoft TightVNC Server for Windows versions before 2.8.88. The integer underflow in WinCursorShapeUtils::trimTransparent() allows an attacker to cause a cursor shape with a width or height of ze [truncated]

MEDIUM GlavSoft CVE published 2026-10-08

CVE-2026-107613

A NULL pointer dereference vulnerability in TightVNC Server Win8ScreenDriver after failed DXGI re-initialization can cause a denial of service. The vulnerability exists in GlavSoft TightVNC Server for Windows before 2.8.88. When re-initialization of the DXGI Desktop Duplication driver fails, m_drvImpl is left NULL and is subsequently dereferenced without a check.

HIGH GlavSoft CVE published 2026-10-08

CVE-2026-107612

A local authenticated user can access and tamper with inter-process communication (IPC) channels in TightVNC Server for Windows before 2.8.88, potentially leading to session data disclosure, privilege escalation, or denial of service. The vulnerability arises from the server creating a world-accessible IPC shared memory with a predictable name, derived from a time-seeded value. This allows a low-privilege [truncated]

HIGH GlavSoft CVE published 2026-10-08

CVE-2026-107611

A vulnerability in TightVNC Viewer for Windows before 2.8.88 allows a malicious VNC server to crash the viewer by sending specially crafted ZRLE-encoded tiles. The vulnerability is due to an out-of-bounds read in the ZRLE decoder, which can lead to the viewer reading heap memory beyond the palette allocation. This can cause the viewer to crash or display garbled content. Defenders should be aware of the p [truncated]