// For flags

CVE-2022-24750

Low privilege user is able to exploit the service and gain SYSTEM privileges in UltraVNC server

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin module, which allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system. The vulnerability has been fixed to allow loading of plugins from the installed directory. Affected users should upgrade their UltraVNC to 1.3.8.1. Users unable to upgrade should not install and run UltraVNC server as a service. It is advisable to create a scheduled task on a low privilege account to launch WinVNC.exe instead. There are no known workarounds if winvnc needs to be started as a service.

UltraVNC es un software de acceso remoto a PC gratuito y de código abierto. Se ha encontrado una vulnerabilidad en versiones anteriores a la 1.3.8.0 en la que el módulo de plugins DSM, que permite a un usuario local autenticado conseguir una escalada de privilegios local (LPE) en un sistema vulnerable. La vulnerabilidad ha sido corregida para permitir la carga de plugins desde el directorio instalado. Los usuarios afectados deben actualizar su UltraVNC a versión 1.3.8.0. Los usuarios que no puedan actualizar no deben instalar y ejecutar el servidor UltraVNC como servicio. Es aconsejable crear una tarea programada en una cuenta con pocos privilegios para lanzar WinVNC.exe en su lugar. No se presentan medidas de mitigación conocidas si wincnc necesita ser iniciado como un servicio

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-10 CVE Reserved
  • 2022-03-10 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Uvnc
Search vendor "Uvnc"
Ultravnc
Search vendor "Uvnc" for product "Ultravnc"
< 1.3.8.1
Search vendor "Uvnc" for product "Ultravnc" and version " < 1.3.8.1"
-
Affected