{"id":"CVE-2026-107614","title":"An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor sh…","summary":"An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor sh…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","cwe":["CWE-125","CWE-191"],"vendor":"GlavSoft","product":"TightVNC","affected":["TightVNC < 2.8.88"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:10:00.133","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107614","references":[{"url":"https://sourceforge.net/p/vnc-tight/bugs/1661/","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://www.tightvnc.com/whatsnew.php","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T14:00:49.369592Z"},"ingestedAt":"2026-10-08T14:47:16.341Z","slug":"CVE-2026-107614","body":"## Overview\n\nAn integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}