CVE-2019-8272
9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.92% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-193 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-03-08 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| siemens | sinumerik access mymachine\/p2p |
| siemens | sinumerik pcu base win10 software\/ipc |
| siemens | sinumerik pcu base win7 software\/ipc |
| uvnc | ultravnc |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19-019-ultravnc-off-by-one-error/
- https://www.us-cert.gov/ics/advisories/icsa-20-161-06
- https://cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2019/03/01/klcert-19-019-ultravnc-off-by-one-error/
- https://www.us-cert.gov/ics/advisories/icsa-20-161-06
→ the Explorer · watch your stack · NVD