Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-4962— UltraVNC Service version.dll uncontrolled search path

CVSS 7.0 · High EPSS 0.01% · P1
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-4962

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UltraVNC Service version.dll uncontrolled search path
Source: NVD (National Vulnerability Database)
Vulnerability Description
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs to be approached locally. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
对搜索路径元素未加控制
Source: NVD (National Vulnerability Database)
Vulnerability Title
UltraVNC 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
UltraVNC是UltraVNC公司的一款用于Windows平台的开源远程终端控制软件。 UltraVNC 1.6.4.0及之前版本存在安全漏洞,该漏洞源于库version.dll中搜索路径不受控制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-UltraVNC 1.6.0 cpe:2.3:a:ultravnc:ultravnc:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-4962

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4962

登录查看更多情报信息。

Same Patch Batch · n/a · 2026-03-27 · 27 CVEs total

CVE-2026-49907.3 HIGHchatwoot Signup Endpoint login improper authorization
CVE-2025-699886.5 MEDIUMBS Producten Petcam 安全漏洞
CVE-2026-49883.7 LOWOpen5GS CCA Message smf_s6b denial of service
CVE-2026-30530SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-30567SourceCodester Inventory System 跨站脚本漏洞
CVE-2026-30568SourceCodester Inventory System 安全漏洞
CVE-2026-30575SourceCodester Pharmacy Product Management System 安全漏洞
CVE-2026-30571SourceCodester Inventory System 跨站脚本漏洞
CVE-2026-30570SourceCodester Inventory System 跨站脚本漏洞
CVE-2026-30569SourceCodester Inventory System 跨站脚本漏洞
CVE-2026-30574SourceCodester Pharmacy Product Management System 安全漏洞
CVE-2026-30576SourceCodester Pharmacy Product Management System 安全漏洞
CVE-2026-30527SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-30529SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-29871Awesome LLM Apps 安全漏洞
CVE-2026-30531SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-30302GitLab CodeRider-Kilo 安全漏洞
CVE-2026-30533SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-30534SourceCodester Online Food Ordering System 安全漏洞
CVE-2026-30532SourceCodester Online Food Ordering System 安全漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-4962

No comments yet


Leave a comment