QID 379101
Date Published: 2023-12-19
QID 379101: UltraVNC Local Privilege Escalation (LPE) Vulnerability
UltraVNC is a powerful and easy to use application that can display the screen of another computer (via Internet or network) on your own screen.
CVE-2022-24750: A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin module, which allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system.
Affected Versions:
UltraVNC before version 1.3.8.1
QID Detection Logic (Authenticated):
The QID checks the version of the executable file located in the installed directory of the software.
Successful exploitation of this vulnerability allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system.
Solution
Users are advised to upgrade to latest version 1.3.8.1 or above. UltraVNC.
Vendor References
CVEs related to QID 379101
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| UltraVNC |
|