LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-7830

uvnc · ultravnc

Published
CVSS7.4
Severityhigh
WeaknessCWE-326
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key exchange is performed with parameters that fit in an unsigned 64-bit integer (DH_MAX_BITS controls the prime size). A 64-bit DH key can be broken by Pollard's rho algorithm in under one second on current hardware. Additionally, the private exponent is generated by the rng() function, which multiplies three libc rand() values seeded from time(NULL). With approximately 31 bits of internal state and a time-based seed, the private exponent is recoverable in under a minute by a passive observer. A network attacker who can observe the MS-L

References

← Back to the CVE Tracker

Our coverage of CVE-2026-7830

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-7830.