Search:     Advanced search
server monitoring

RealVNC VNC Viewer < 4.1.3/4.4.3 Arbitrary Command Execution

Article ID: 34461
Last updated: 27 Jan, 2009
Views: 794
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

RealVNC VNC Viewer < 4.1.3/4.4.3 Arbitrary Command Execution

This script is Copyright (C) 2008 Tenable Network Security, Inc.

FamilyWindows
Plugin ID34461
Bugtraq ID31832
33263
CVE IDCVE-2008-4770

Description:
Synopsis :

The remote Windows host has an application that may allow execution of
arbitrary code.

Description :

The version of RealVNCs VNC Viewer installed on the remote Windows
host is affected by multiple issues :

- An error in the CMsgReader::readRect() function in
common/rfb/CMsgReader.cxx that comes into play when
processing encoding types, may allow arbitrary code
execution on the remote system. If an attacker can trick
a user on the remote host into connecting to a malicious
server, he can exploit this issue using specially crafted
messages to compromise that host.

- By tricking an user to connect to an malicious VNC server
it may be possible for an attacker to execute arbitrary
code on remote system by sending malicious RFB protocol
data to the remote VNC Viewer component. Note VNC servers
are not affected by this issue.

See also :

http://www.realvnc.com/products/upgrade.html
http://www.realvnc.com/products/free/4.1/release-notes.html
http://www.realvnc.com/products/personal/4.4/release-notes.html
http://www.realvnc.com/products/enterprise/4.4/release-notes.html

Solution :

Upgrade to RealVNC VNC Viewer Free Edition 4.1.3 / Personal Edition
4.4.3 / Enterprise Edition 4.4.3 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Microsoft Dynamics GP < 10.0 Multiple Vulnerabilities     SizerOne ActiveX Control AddTab Method Remote Buffer Overflow