PT-2026-54486 · Ultravnc · Ultravnc

·

CVE-2026-7830

·

Published

2026-07-01

·

Updated

2026-07-09

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions UltraVNC versions prior to 1.8.2.3
Description Inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC MsLogonIIAuth) allows a network attacker to disclose credentials. In the file rfb/dh.cpp, the Diffie-Hellman key exchange uses parameters fitting in an unsigned 64-bit integer, controlled by DH MAX BITS. Such keys can be broken quickly using Pollard's rho algorithm. Furthermore, the rng() function generates the private exponent by multiplying three libc rand() values seeded from time(NULL), making the exponent recoverable by a passive observer due to the limited internal state and time-based seed. An attacker observing the MS-Logon II handshake can derive the shared DH key to decrypt the username and password. This issue only affects legacy MS-Logon II connections.
Recommendations Update to a version newer than 1.8.2.2. Restrict the use of the MS-Logon II authentication scheme to minimize the risk of credential disclosure.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7830

Affected Products

Ultravnc