Vulnerability record · CVE-2001-0167 · published 3 May 2001
CVE-2001-0167: AT&T WinVNC client buffer overflow via rfbConnFailed reason string
Att · Winvnc
AT&T WinVNC client 3.3.3r7 and earlier contains a buffer overflow in its handling of the rfbConnFailed packet, triggered by an overly long reason string. A remote attacker who can deliver a crafted packet to the client can corrupt memory and potentially execute arbitrary commands. The flaw matters because VNC clients are commonly run on administrator and user workstations, and the record gives no indication of a required local position.
Description
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with complete impact and a very high EPSS score, though the high access complexity and lack of confirmed in-the-wild exploitation temper it below critical.
What it is
AT&T WinVNC client 3.3.3r7 and earlier contains a buffer overflow in its handling of the rfbConnFailed packet, triggered by an overly long reason string. A remote attacker who can deliver a crafted packet to the client can corrupt memory and potentially execute arbitrary commands. The flaw matters because VNC clients are commonly run on administrator and user workstations, and the record gives no indication of a required local position.
Impact
Successful exploitation allows remote code execution with the privileges of the WinVNC client process, giving the attacker command execution on the victim host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network through the RFB protocol when the WinVNC client processes a malicious rfbConnFailed packet; the vector (AV:N/Au:N) indicates no authentication is required. The high access complexity (AC:H) suggests the attacker needs specific conditions or positioning, and no user interaction is stated in the record.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.50813, 98.87th percentile), and the SecurityFocus reference carries Patch and Vendor Advisory tags, but the record contains no public exploit or in-the-wild confirmation.
What to do
- Apply the vendor patch referenced in the SecurityFocus advisory (BID 2305) or upgrade WinVNC past 3.3.3r7.
- If patching is not possible, restrict network access to VNC client hosts and block untrusted RFB traffic at the perimeter.
- Run the WinVNC client with least privilege so a successful overflow does not yield administrative rights.
- Retire or isolate the unsupported AT&T WinVNC 3.3.3r7 client in favor of a maintained VNC implementation.
Detection
- Monitor for WinVNC client crashes or abnormal process termination that could indicate a malformed rfbConnFailed packet.
- Inspect network traffic for RFB connection-failure messages containing unusually long reason strings.
- Alert on unexpected child processes or command execution spawned by the WinVNC client process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0167 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0167), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.