← Vulnerability feed

Vulnerability record · CVE-2026-3787 · published 8 March 2026

CVE-2026-3787: Uvnc ultravnc untrusted search path vulnerability

Uvnc · Ultravnc

A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

6.4 CVSS 4.0 Medium EPSS 0.18% · top 92.7% CWE-426 · Untrusted search pathCWE-427 · Uncontrolled search path element
6.4CVSS 4.0 base score, v2 6.0
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://drive.google.com/file/d/14ixv_1i4D2VrZWyl4RKsvFcN1AMF_qNx/view Permissions Required
https://vuldb.com/?ctiid.349754 Permissions RequiredVDB Entry
https://vuldb.com/?id.349754 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.767257 Third Party AdvisoryVDB Entry

Track CVE-2026-3787 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-8268Uvnc ultravnc vulnerabilityUltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString funct…EPSS 3.9%9.8CVE-2019-8273Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result…EPSS 8.3%9.8CVE-2019-8280Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This att…EPSS 4.2%9.8CVE-2019-8266Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnection::Copybuffer function in VN…EPSS 2.8%9.8CVE-2019-8271Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code ex…EPSS 8.3%9.8CVE-2019-8264Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. Th…EPSS 3.1%9.8CVE-2019-8274Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in resul…EPSS 8.3%9.8CVE-2019-8272Uvnc ultravnc vulnerabilityUltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appear…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-3787), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.