CVE-2026-7831: Off-by-one Error in uvnc UltraVNC
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn[2024], one byte past the end of the stack buffer. A malicious VNC server can trigger this condition by advertising a desktop name of length 2024 in its ServerInit message. On release builds without stack canaries the single-byte NUL overwrite adjacent stack data. On builds with /GS stack protection the canary is corrupted and the process terminates, resulting in denial of service. User interaction (connecting the viewer to the malicious server) is required.
AI Analysis
Technical Summary
CVE-2026-7831 is an off-by-one stack buffer overflow in UltraVNC viewer (up to version 1.8.2.2) within the RFB ServerInit message handler. When the server-supplied desktop name length is exactly 2024, the code allocates a 2024-byte stack buffer and calls ReadString which writes a NUL terminator one byte beyond the buffer boundary. On builds without stack canaries, this overwrites adjacent stack data by one byte, potentially causing undefined behavior. On builds with /GS stack protection, the canary is corrupted, causing the process to terminate and resulting in denial of service. Exploitation requires the user to connect the viewer to a malicious VNC server that sends a crafted ServerInit message.
Potential Impact
The vulnerability allows a malicious VNC server to cause a denial of service by crashing the UltraVNC viewer process due to stack corruption. On builds without stack protection, the single-byte overflow may lead to memory corruption with potential for limited code execution, but this is not explicitly confirmed. User interaction is required to trigger the vulnerability by connecting to a malicious server. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid connecting UltraVNC viewer to untrusted or malicious VNC servers to prevent exploitation. Monitor vendor channels for updates and apply official patches once released.
CVE-2026-7831: Off-by-one Error in uvnc UltraVNC
Description
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls ReadString(_dn, 2024). ReadString writes the NUL terminator at buf[length], i.e., _dn[2024], one byte past the end of the stack buffer. A malicious VNC server can trigger this condition by advertising a desktop name of length 2024 in its ServerInit message. On release builds without stack canaries the single-byte NUL overwrite adjacent stack data. On builds with /GS stack protection the canary is corrupted and the process terminates, resulting in denial of service. User interaction (connecting the viewer to the malicious server) is required.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7831 is an off-by-one stack buffer overflow in UltraVNC viewer (up to version 1.8.2.2) within the RFB ServerInit message handler. When the server-supplied desktop name length is exactly 2024, the code allocates a 2024-byte stack buffer and calls ReadString which writes a NUL terminator one byte beyond the buffer boundary. On builds without stack canaries, this overwrites adjacent stack data by one byte, potentially causing undefined behavior. On builds with /GS stack protection, the canary is corrupted, causing the process to terminate and resulting in denial of service. Exploitation requires the user to connect the viewer to a malicious VNC server that sends a crafted ServerInit message.
Potential Impact
The vulnerability allows a malicious VNC server to cause a denial of service by crashing the UltraVNC viewer process due to stack corruption. On builds without stack protection, the single-byte overflow may lead to memory corruption with potential for limited code execution, but this is not explicitly confirmed. User interaction is required to trigger the vulnerability by connecting to a malicious server. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid connecting UltraVNC viewer to untrusted or malicious VNC servers to prevent exploitation. Monitor vendor channels for updates and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- securin
- Date Reserved
- 2026-05-05T04:03:22.622Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a44a07a27e9c79719fbd73e
Added to database: 07/01/2026, 05:07:06 UTC
Last enriched: 07/08/2026, 12:54:42 UTC
Last updated: 08/15/2026, 00:41:15 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.