CVE-2026-107614: Glavsoft Tightvnc

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.

Affected products

  • Glavsoft Tightvnc: before 2.8.88 (fixed in 2.8.88)

Published 2026-10-08. Last modified 2026-10-08.