CVE-2020-37133
7.5UltraVNC · Launcher
UltraVNC Launcher 1.2.4.0 is susceptible to a stack-based buffer overflow in the Repeater Host configuration field, allowing local attackers to cause a denial of service via an overly long string.
Executive summary
A stack-based buffer overflow vulnerability in UltraVNC Launcher 1.2.4.0 allows local attackers to crash the application, resulting in a denial of service.
Vulnerability
The application fails to properly validate input length within the Repeater Host property field. By pasting a 300 character string into this field, an attacker with local access can trigger a stack-based buffer overflow, forcing the application to crash.
Business impact
Successful exploitation of this vulnerability results in a denial of service condition for the UltraVNC Launcher application. While the impact is limited to local application availability, the resulting disruption can hinder administrative tasks or remote support operations. The CVSS score of 7.5 reflects the potential for service instability, although the requirement for local interaction limits the overall attack surface.
Remediation
Immediate Action: There is currently no confirmed patch available for this specific issue. Users are advised to restrict physical or local access to systems running the vulnerable software to prevent unauthorized modification of application properties.
Proactive Monitoring: Security teams should monitor system logs for frequent application crashes or unexpected service termination events associated with the UltraVNC Launcher process.
Compensating Controls: Implement strict endpoint access controls and maintain updated antivirus or EDR solutions to detect and block unauthorized execution of malicious scripts or exploit attempts on the host system.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via ExploitDB (EDB-ID 48288).
Analyst recommendation
Given that this vulnerability allows for an intentional service disruption, organizations should prioritize limiting local access to the UltraVNC configuration interface. Because no vendor patch is currently available, it is essential to employ compensating administrative controls to ensure only authorized personnel have the ability to modify application settings on sensitive endpoints.
More UltraVNC CVEs
Sources
Originally found and disclosed by chuyreds, per the CVE Program record.
- ExploitDB-48288 Exploit / PoC
- UltraVNC Official Homepage
- VulnCheck Advisory: UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service Third-party advisory