CVE-2020-37134
7.5UltraVNC · Viewer
UltraVNC Viewer 1.2.4.0 is susceptible to a denial of service vulnerability caused by improper input validation, allowing an attacker to crash the application using a malformed payload.
Executive summary
A denial of service vulnerability in UltraVNC Viewer 1.2.4.0 allows unauthenticated attackers to crash the application by submitting a malformed connection string.
Vulnerability
The application fails to properly throttle or limit resource allocation when processing input in the VNC Server connection dialog. By providing a 256-byte malformed payload, an unauthenticated user can trigger an application crash, resulting in a denial of service.
Business impact
While the CVSS score of 7.5 indicates a high severity, the practical impact is limited to a denial of service on the specific machine running the viewer. A successful exploit disrupts remote administration capabilities, potentially hindering IT operations and causing temporary service outages for users reliant on remote access.
Remediation
Immediate Action: Upgrade to a version of UltraVNC Viewer beyond 1.2.4.0 to resolve the underlying resource management flaw. If an update is not immediately feasible, restrict access to the VNC Viewer application to authorized personnel only.
Proactive Monitoring: Review system and application logs for repeated crash events or unusual connection attempts directed at the VNC Viewer interface.
Compensating Controls: Implement endpoint security policies that restrict the execution of remote access tools to hardened management workstations, reducing the attack surface.
Exploitation status
Public Exploit Available: Yes, a proof of concept exists, as documented in the Exploit Database (EDB-ID: 48291).
Analyst recommendation
Organizations utilizing UltraVNC Viewer 1.2.4.0 should prioritize updating to a newer, patched release to eliminate this vulnerability. Given the ease of exploitation, maintaining outdated versions of remote access software poses an unnecessary risk to administrative continuity and infrastructure availability.
More UltraVNC CVEs
Sources
Originally found and disclosed by chuyreds, per the CVE Program record.
- ExploitDB-48291 Exploit / PoC
- UltraVNC Official Homepage
- VulnCheck Advisory: UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service Third-party advisory