Kaspersky researchers have discovered 37 vulnerabilities in four well-known open-source VNC remote desktop applications. The vulnerabilities have existed since 1999 and allow malicious hackers to gain access and compromise systems victims'
According to researchers, attackers have gained remote access to more than 600,000 VNC serversover the Internet, using data collected through the Shodan search engine.
37 vulnerabilities found
Researchers discovered 37 vulnerabilities in four VNC applications: 10 vulnerabilities were found in LibVNC, 4 in TightVNC 1.X, 1 in TurboVNC , and 22 in UltraVNC.
VNC applications are available in many versions and are compatible with popular operating systems such as Windows, Linux, macOS, and Android.
VNC applications contain two components. One is deployed on the server and the other on the client, which is used to gain access to the server.
Researchers discovered vulnerabilities in both the server and client that cause a memory. This problem in turn leads to other malfunctions, while also allowing denial of service attacks.
In some cases, vulnerabilities allow hackers to gain unauthorized access to devices or develop malicious programs.

How can the attack be carried out:
- The attacker is on the same network as the VNC server and is attacking to gain the ability to execute code on the server.
- A user connects to an attacker's server using a VNC client, and the attacker exploits vulnerabilities in the client to attack the user and execute code on their machine.
Most vulnerabilities have already been fixed, except for those in TightVNC 1.x, which is no longer supported. TightVNC 2.X versions are now in use.
The researchers recommend that users use strong passwords and monitor their devices, and that they avoid connecting to untrusted or untested VNC servers.
