Vulnerability Description
UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uvnc | Ultravnc | < 1.2.2.3 |
| Siemens | Sinumerik Access Mymachine\/P2P | < 4.8 |
| Siemens | Sinumerik Pcu Base Win10 Software\/Ipc | < 14.00 |
| Siemens | Sinumerik Pcu Base Win7 Software\/Ipc | <= 12.01 |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdfThird Party Advisory
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19Third Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-161-06Third Party AdvisoryUS Government Resource
- https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdfThird Party Advisory
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19Third Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-161-06Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-8272?
CVE-2019-8272 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These...
How severe is CVE-2019-8272?
CVE-2019-8272 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-8272?
Check the references section above for vendor advisories and patch information. Affected products include: Uvnc Ultravnc, Siemens Sinumerik Access Mymachine\/P2P, Siemens Sinumerik Pcu Base Win10 Software\/Ipc, Siemens Sinumerik Pcu Base Win7 Software\/Ipc.