UltraVNC Viewer VNC client RFB SolidColor Arbitrary Write Vulnerability

December 16, 2021 No Comments
EIP-0e1ca3ec A vulnerability exists within UltraVNC’s “vncviewer.exe” client. A malicious server can trigger an arbitrary memory write condition through a flaw in the function ClientConnection::SolidColor while drawing pixel data to the screen. An attacker can leverage this in conjunction with other vulnerabilities
Read More »

UltraVNC Viewer VNC client RFB rfbServerInitMsg Heap Overflow Vulnerability

December 16, 2021 No Comments
EIP-0e1ca3ec A vulnerability exists within UltraVNC’s “vncviewer.exe” client. Specifically a malicious server may write arbitrary data to arbitrary memory locations through the  in the “rfbServerInitMsg” function upon parsing a long ‘nameLength’ field returned from a nefarious server. An attacker can leverage this
Read More »

UltraVNC Viewer VNC client RFB ReadUltraRect Heap Overflow Vulnerability

December 16, 2021 No Comments
EIP-930b0ea5 A vulnerability exists within UltraVNC’s “vncviewer.exe” client. Specifically a heap overflow can be triggered in the “ClientConnection::ReadUltraRect” function upon decompression of malicious formatted data returned from a nefarious server. An attacker can leverage this in conjunction with other vulnerabilities to execute
Read More »

UltraVNC Viewer VNC client Remote Memory Leak Vulnerability

December 2, 2021 No Comments
EIP-5182fb5b A vulnerability exists within UltraVNC view due to a lack of proper stack memory buffer cleanup before constructing the ‘rfbTextChat’ message, which results in a leak of 3-bytes of stack memory. An attacker can leverage this in conjunction with other vulnerabilities
Read More »

NEC EXPRESSCLUSTER X Web Manager File Upload Vulnerability

October 31, 2021 No Comments
EIP-d8554689 An arbitrary file upload vulnerability has been found in NEC EXPRESSCLUSTER X. WebManager (clpwebmc.exe) is a webserver tasked with providing remote administrative access, it is configured to utilize port 29003 by default. This vulnerability occurs due to lack of input validation
Read More »

NEC EXPRESSCLUSTER X Web Manager Command Execution Vulnerability

October 31, 2021 No Comments
EIP-9eccc486 A remote command execution vulnerability has been found in NEC EXPRESSCLUSTER X. WebManager (clpwebmc.exe) is a webserver tasked with providing remote administrative access, it is configured to utilize port 29003 by default. This vulnerability occurs due to a command injection vulnerability
Read More »

NEC EXPRESSCLUSTER X Disk Agent 0x104 Stack Overflow Vulnerability

October 31, 2021 No Comments
EIP-8b0cfb43 A stack-based buffer overflow has been found in NEC EXPRESSCLUSTER X that can lead to remote arbitrary code execution with full SYSTEM privileges. The Disk Agent (clpdiskagent.exe) is the component that is tasked with handling shared disk resources and mirror disk
Read More »

NEC EXPRESSCLUSTER X Disk Agent 0x103 Stack Overflow Vulnerability

October 31, 2021 No Comments
EIP-ff1ca610 A stack-based buffer overflow has been found in NEC EXPRESSCLUSTER X that can lead to remote arbitrary code execution with full SYSTEM privileges. The Disk Agent (clpdiskagent.exe) is the component that is tasked with handling shared disk resources and mirror disk
Read More »