QID 379101

Date Published: 2023-12-19

QID 379101: UltraVNC Local Privilege Escalation (LPE) Vulnerability

UltraVNC is a powerful and easy to use application that can display the screen of another computer (via Internet or network) on your own screen.

CVE-2022-24750: A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin module, which allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system.
Affected Versions:
UltraVNC before version 1.3.8.1

QID Detection Logic (Authenticated):
The QID checks the version of the executable file located in the installed directory of the software.

Successful exploitation of this vulnerability allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Users are advised to upgrade to latest version 1.3.8.1 or above. UltraVNC.

    CVEs related to QID 379101

    Software Advisories
    Advisory ID Software Component Link
    UltraVNC URL Logo uvnc.com/downloads/ultravnc/150-ultravnc-1-3-8-1.html