Vulnerability record · CVE-2001-0168 · published 3 May 2001
CVE-2001-0168: AT&T WinVNC server buffer overflow via long HTTP GET request
Att · Winvnc
AT&T WinVNC server 3.3.3r7 and earlier contains a buffer overflow that is triggered by a long HTTP GET request when the DebugLevel registry key is greater than 0. Because the overflow is remotely reachable and can lead to arbitrary command execution, it is a serious pre-authentication risk for any exposed WinVNC service. The record does not list a CVSS v3 score, so severity is taken from the CVSS v2 rating of 10.0.
Description
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and yields full command execution, but a patch and vendor advisory exist and there is no confirmed active exploitation in KEV.
What it is
AT&T WinVNC server 3.3.3r7 and earlier contains a buffer overflow that is triggered by a long HTTP GET request when the DebugLevel registry key is greater than 0. Because the overflow is remotely reachable and can lead to arbitrary command execution, it is a serious pre-authentication risk for any exposed WinVNC service. The record does not list a CVSS v3 score, so severity is taken from the CVSS v2 rating of 10.0.
Impact
A remote attacker can execute arbitrary commands on the WinVNC host, giving full control of the machine under the privileges of the service. This can lead to data theft, service disruption, or use of the host as a pivot point.
Attack surface
The flaw is reached over the network through the WinVNC HTTP interface by sending a crafted long GET request. The CVSS v2 vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, though the DebugLevel registry key must be greater than 0 for the overflow to trigger.
Exploitation
The record is not listed in CISA KEV and no ransomware groups are documented as using it. EPSS gives a 30-day probability of 0.7073 (99.365th percentile), and references include a Patch and Vendor Advisory tag, indicating a fix exists but active exploitation is not confirmed by the supplied data.
What to do
- Apply the vendor patch referenced in the SecurityFocus advisory (bid 2306) or upgrade WinVNC beyond 3.3.3r7.
- Set the DebugLevel registry key to 0 or remove it where the patch cannot be applied immediately.
- Restrict network access to the WinVNC HTTP port to trusted hosts only, and block it at the perimeter.
- Disable or remove the WinVNC service on systems that do not require remote console access.
- Monitor vendor advisories for any updated guidance on this legacy product.
Detection
- Inspect WinVNC server logs for unusually long or malformed HTTP GET requests.
- Monitor network traffic to the WinVNC HTTP port for oversized GET requests or shell-like payload patterns.
- Audit the DebugLevel registry key on WinVNC hosts to confirm it is 0 or absent.
- Watch for unexpected child processes or command execution spawned by the WinVNC service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=vnc-list&m=98080763005455&w=2 | |
| http://www.kb.cert.org/vuls/id/598581 | US Government Resource |
| http://www.securityfocus.com/bid/2306 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6026 | |
| http://marc.info/?l=vnc-list&m=98080763005455&w=2 | |
| http://www.kb.cert.org/vuls/id/598581 | US Government Resource |
| http://www.securityfocus.com/bid/2306 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6026 |
Track CVE-2001-0168 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0168), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.