QID 378487
Date Published: 2023-05-18
QID 378487: TightVNC Privilege Escalation Vulnerability
In computing, TightVNC is a free and open-source remote desktop software server and client application for Linux and Windows
ightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account..
Affected Software:
TightVNC version upto 2.8.75.0
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of TightVNC using .exe file.
Allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer.
Solution
Upgrade to TightVNC Refer to TightVNC
Vendor References
- TightVNC 2.8.75 -
www.tightvnc.com/whatsnew.php
CVEs related to QID 378487
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TightVNC |
|