Post cover image

May 12, 2026

UltraVNC < 1.8.1.2- Unsafe CreateProcess Call Enables Arbitrary EXE Execution as SYSTEM (CWE-428)

UltraVNC <1.8.1.2 allows arbitrary EXE execution as SYSTEM via unsafe CreateProcess Calls. Coupled with a file transfer config, allows RCE

Elpfarr

4 min read