← Vulnerability feed

Vulnerability record · CVE-2001-0168 · published 3 May 2001

CVE-2001-0168: AT&T WinVNC server buffer overflow via long HTTP GET request

Att · Winvnc

AT&T WinVNC server 3.3.3r7 and earlier contains a buffer overflow that is triggered by a long HTTP GET request when the DebugLevel registry key is greater than 0. Because the overflow is remotely reachable and can lead to arbitrary command execution, it is a serious pre-authentication risk for any exposed WinVNC service. The record does not list a CVSS v3 score, so severity is taken from the CVSS v2 rating of 10.0.

10.0 CVSS 2.0 High EPSS 71% · top 0.6%
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and yields full command execution, but a patch and vendor advisory exist and there is no confirmed active exploitation in KEV.

What it is

AT&T WinVNC server 3.3.3r7 and earlier contains a buffer overflow that is triggered by a long HTTP GET request when the DebugLevel registry key is greater than 0. Because the overflow is remotely reachable and can lead to arbitrary command execution, it is a serious pre-authentication risk for any exposed WinVNC service. The record does not list a CVSS v3 score, so severity is taken from the CVSS v2 rating of 10.0.

Impact

A remote attacker can execute arbitrary commands on the WinVNC host, giving full control of the machine under the privileges of the service. This can lead to data theft, service disruption, or use of the host as a pivot point.

Attack surface

The flaw is reached over the network through the WinVNC HTTP interface by sending a crafted long GET request. The CVSS v2 vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, though the DebugLevel registry key must be greater than 0 for the overflow to trigger.

Exploitation

The record is not listed in CISA KEV and no ransomware groups are documented as using it. EPSS gives a 30-day probability of 0.7073 (99.365th percentile), and references include a Patch and Vendor Advisory tag, indicating a fix exists but active exploitation is not confirmed by the supplied data.

What to do

  • Apply the vendor patch referenced in the SecurityFocus advisory (bid 2306) or upgrade WinVNC beyond 3.3.3r7.
  • Set the DebugLevel registry key to 0 or remove it where the patch cannot be applied immediately.
  • Restrict network access to the WinVNC HTTP port to trusted hosts only, and block it at the perimeter.
  • Disable or remove the WinVNC service on systems that do not require remote console access.
  • Monitor vendor advisories for any updated guidance on this legacy product.

Detection

  • Inspect WinVNC server logs for unusually long or malformed HTTP GET requests.
  • Monitor network traffic to the WinVNC HTTP port for oversized GET requests or shell-like payload patterns.
  • Audit the DebugLevel registry key on WinVNC hosts to confirm it is 0 or absent.
  • Watch for unexpected child processes or command execution spawned by the WinVNC service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0168 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2001-0168), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.