CVE-2026-3787
UltraVNC vulnerability analysis and mitigation

Overview

CVE-2026-3787 is an uncontrolled search path (DLL hijacking) vulnerability in UltraVNC 1.6.4.0 on Windows, specifically affecting the cryptbase.dll library loaded by the UltraVNC Windows Service component. The vulnerability was published on March 8, 2026, and was assigned by VulDB. It carries a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 6.4 (Medium) (VulDB, ENISA EUVD). The vendor was contacted prior to disclosure but did not respond (VulDB).

Technical details

The vulnerability is classified under CWE-426 (Untrusted Search Path) and CWE-427 (Uncontrolled Search Path Element), and maps to MITRE ATT&CK technique T1574.001 (DLL Search Order Hijacking) (ENISA EUVD). The UltraVNC Windows Service loads cryptbase.dll without specifying an absolute path, allowing an attacker with local access to place a malicious DLL in a directory that is searched before the legitimate system location. Exploitation requires local access and is rated as high complexity, meaning specific conditions or timing may be required to succeed (VulDB). A proof-of-concept has been referenced in the vulnerability disclosure (Google Drive PoC).

Impact

Successful exploitation allows a local attacker to achieve high impact on confidentiality, integrity, and availability of the affected system. Because the UltraVNC Windows Service typically runs with elevated privileges, a malicious cryptbase.dll loaded by the service could grant the attacker SYSTEM-level code execution, enabling full system compromise, credential theft, and potential lateral movement within the network (VulDB, ENISA EUVD).

Exploitability

A proof-of-concept has been publicly referenced as part of the disclosure (Google Drive PoC), and the CVSS v4.0 exploit maturity is rated as "Proof of Concept" (ENISA EUVD). The EPSS score is very low at approximately 0.005%, indicating limited automated exploitation probability at this time (VulDB). There is no evidence of active in-the-wild exploitation or CISA KEV catalog inclusion as of the available data. The attack requires local access and high complexity, limiting its practical exploitability to targeted scenarios.

Exploitation steps

  1. Reconnaissance: Identify a Windows system running UltraVNC 1.6.4.0 with the UltraVNC Windows Service active. Confirm the service is running and determine the DLL search path order used by the service process.
  2. Identify vulnerable DLL load path: Determine that the UltraVNC Windows Service loads cryptbase.dll without an absolute path, causing Windows to search directories in a predictable order (e.g., application directory, current working directory, system directories).
  3. Craft malicious DLL: Create a malicious cryptbase.dll that exports the same functions as the legitimate Windows cryptbase.dll while also executing attacker-controlled code (e.g., a reverse shell or privilege escalation payload).
  4. Place malicious DLL: With local user access, write the malicious cryptbase.dll to a directory that is searched before C:\Windows\System32\ in the service's DLL search order (e.g., the UltraVNC application directory, if writable).
  5. Trigger service load: Wait for or trigger a restart of the UltraVNC Windows Service (e.g., via system reboot or service restart if the user has appropriate permissions). The service loads the malicious DLL instead of the legitimate one.
  6. Achieve elevated code execution: The malicious DLL executes in the context of the Windows Service (typically SYSTEM), granting the attacker full control of the host (VulDB, Google Drive PoC).

Indicators of compromise

  • File System: Presence of an unexpected cryptbase.dll in the UltraVNC installation directory (e.g., C:\Program Files\UltraVNC\) or any directory in the service's DLL search path outside of C:\Windows\System32\.
  • Process: Unusual child processes spawned by the UltraVNC service process (e.g., cmd.exe, powershell.exe, net.exe) with SYSTEM privileges.
  • Logs: Windows Event Log entries (Event ID 7045 or 7036) showing unexpected UltraVNC service restarts; Process creation events (Event ID 4688 or Sysmon Event ID 1) showing suspicious processes launched by the UltraVNC service.
  • Network: Unexpected outbound network connections originating from the UltraVNC service process to external IP addresses, potentially indicating a reverse shell or C2 beacon.

Mitigation and workarounds

UltraVNC has released version 1.8.2.2, which is available from the official vendor download page and should be applied to remediate this and other vulnerabilities (UltraVNC Downloads). As a workaround prior to patching, administrators should ensure that the UltraVNC installation directory and any directories in the service's DLL search path are not writable by unprivileged users. Additionally, enabling Windows Safe DLL Search Mode and applying the principle of least privilege to service accounts can reduce the risk of exploitation.

Community reactions

The vulnerability received limited but notable coverage across security aggregation platforms and social media shortly after disclosure. Posts were observed on Bluesky from CVE tracking accounts, and the vulnerability was indexed by multiple threat intelligence feeds including INCIBE-CERT and Red Packet Security (INCIBE-CERT, Red Packet Security). The UltraVNC vendor did not respond to the researcher's disclosure, which was noted as a concern in the advisory (VulDB).

Additional resources


SourceThis report was generated using AI

Related UltraVNC vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2009-0388HIGH10
  • TightVNC logoTightVNC
  • cpe:2.3:a:tightvnc:tightvnc
NoYesFeb 04, 2009
CVE-2008-5001HIGH9.3
  • UltraVNC logoUltraVNC
  • cpe:2.3:a:ultravnc:ultravnc
NoYesNov 10, 2008
CVE-2010-5248MEDIUM6.9
  • UltraVNC logoUltraVNC
  • cpe:2.3:a:ultravnc:ultravnc
NoYesSep 07, 2012
CVE-2026-4962MEDIUM6.4
  • UltraVNC logoUltraVNC
  • cpe:2.3:a:ultravnc:ultravnc
NoNoMar 27, 2026
CVE-2026-3787MEDIUM6.4
  • UltraVNC logoUltraVNC
  • cpe:2.3:a:ultravnc:ultravnc
NoNoMar 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management