← Vulnerability feed

Vulnerability record · CVE-2026-7831 · published 1 July 2026

CVE-2026-7831: Uvnc ultravnc out-of-bounds write vulnerability

Uvnc · Ultravnc

UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn[2024], one byte past the end of the stack buffer. A malicious VNC server can trigger this condition by advertising a desktop name of length 2024 in its ServerInit message. On release builds without stack canaries the single-byte NUL overwrite adjacent stack data. On builds with /GS stack protection the canary is corrupted and the process terminates, resulting in denial of service. User interaction (connecting the viewer to the malicious server) is required.

7.6 CVSS 3.1 High EPSS 0.74% · top 47.3% CWE-193 · CWE-193CWE-787 · Out-of-bounds write
7.6CVSS 3.1 base score
0.74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
9 Jul 2026Last modified by NVD

Description

UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn[2024], one byte past the end of the stack buffer. A malicious VNC server can trigger this condition by advertising a desktop name of length 2024 in its ServerInit message. On release builds without stack canaries the single-byte NUL overwrite adjacent stack data. On builds with /GS stack protection the canary is corrupted and the process terminates, resulting in denial of service. User interaction (connecting the viewer to the malicious server) is required.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7831 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-8264Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. Th…EPSS 3.1%9.8CVE-2019-8265Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which c…EPSS 3.1%9.8CVE-2019-8266Uvnc ultravnc out-of-bounds read vulnerabilityUltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnection::Copybuffer function in VN…EPSS 2.8%9.8CVE-2019-8268Uvnc ultravnc vulnerabilityUltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString funct…EPSS 3.9%9.8CVE-2019-8271Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code ex…EPSS 8.3%9.8CVE-2019-8272Uvnc ultravnc vulnerabilityUltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appear…EPSS 3.9%9.8CVE-2019-8273Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result…EPSS 8.3%9.8CVE-2019-8274Uvnc ultravnc heap-based buffer overflow vulnerabilityUltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in resul…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2026-7831), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.