
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3787 is an uncontrolled search path (DLL hijacking) vulnerability in UltraVNC 1.6.4.0 on Windows, specifically affecting the cryptbase.dll library loaded by the UltraVNC Windows Service component. The vulnerability was published on March 8, 2026, and was assigned by VulDB. It carries a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 6.4 (Medium) (VulDB, ENISA EUVD). The vendor was contacted prior to disclosure but did not respond (VulDB).
The vulnerability is classified under CWE-426 (Untrusted Search Path) and CWE-427 (Uncontrolled Search Path Element), and maps to MITRE ATT&CK technique T1574.001 (DLL Search Order Hijacking) (ENISA EUVD). The UltraVNC Windows Service loads cryptbase.dll without specifying an absolute path, allowing an attacker with local access to place a malicious DLL in a directory that is searched before the legitimate system location. Exploitation requires local access and is rated as high complexity, meaning specific conditions or timing may be required to succeed (VulDB). A proof-of-concept has been referenced in the vulnerability disclosure (Google Drive PoC).
Successful exploitation allows a local attacker to achieve high impact on confidentiality, integrity, and availability of the affected system. Because the UltraVNC Windows Service typically runs with elevated privileges, a malicious cryptbase.dll loaded by the service could grant the attacker SYSTEM-level code execution, enabling full system compromise, credential theft, and potential lateral movement within the network (VulDB, ENISA EUVD).
A proof-of-concept has been publicly referenced as part of the disclosure (Google Drive PoC), and the CVSS v4.0 exploit maturity is rated as "Proof of Concept" (ENISA EUVD). The EPSS score is very low at approximately 0.005%, indicating limited automated exploitation probability at this time (VulDB). There is no evidence of active in-the-wild exploitation or CISA KEV catalog inclusion as of the available data. The attack requires local access and high complexity, limiting its practical exploitability to targeted scenarios.
cryptbase.dll without an absolute path, causing Windows to search directories in a predictable order (e.g., application directory, current working directory, system directories).cryptbase.dll that exports the same functions as the legitimate Windows cryptbase.dll while also executing attacker-controlled code (e.g., a reverse shell or privilege escalation payload).cryptbase.dll to a directory that is searched before C:\Windows\System32\ in the service's DLL search order (e.g., the UltraVNC application directory, if writable).cryptbase.dll in the UltraVNC installation directory (e.g., C:\Program Files\UltraVNC\) or any directory in the service's DLL search path outside of C:\Windows\System32\.cmd.exe, powershell.exe, net.exe) with SYSTEM privileges.UltraVNC has released version 1.8.2.2, which is available from the official vendor download page and should be applied to remediate this and other vulnerabilities (UltraVNC Downloads). As a workaround prior to patching, administrators should ensure that the UltraVNC installation directory and any directories in the service's DLL search path are not writable by unprivileged users. Additionally, enabling Windows Safe DLL Search Mode and applying the principle of least privilege to service accounts can reduce the risk of exploitation.
The vulnerability received limited but notable coverage across security aggregation platforms and social media shortly after disclosure. Posts were observed on Bluesky from CVE tracking accounts, and the vulnerability was indexed by multiple threat intelligence feeds including INCIBE-CERT and Red Packet Security (INCIBE-CERT, Red Packet Security). The UltraVNC vendor did not respond to the researcher's disclosure, which was noted as a concern in the advisory (VulDB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."