UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
| Software | From | Fixed in |
|---|---|---|
| uvnc / ultravnc | - | 1.2.2.3 |
| siemens / sinumerik_pcu_base_win7_software/ipc | - | 12.01.x |
| siemens / sinumerik_pcu_base_win10_software/ipc | - | 14.00 |
| siemens / sinumerik_access_mymachine/p2p | - | 4.8 |