CVE-2019-15690

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 122

Summary

CVE-2019-15690 is a critical vulnerability affecting LibVNCServer versions 0.9.12 and older. This issue involves a heap buffer overflow in the HandleCursorShape() function, located in libvncclient/cursor.c. The vulnerability arises when an attacker sends cursor shapes with maliciously crafted dimensions. Successful exploitation of this flaw can lead to remote code execution, potentially giving an attacker full control over an affected system. It is important to note that updating to the latest version of LibVNCServer can mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share