CVE-2020-37132

Severity CVSS v4.0:
MEDIUM
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
05/02/2026
Last modified:
09/02/2026

Description

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uvnc:ultravnc:*:*:*:*:*:*:*:* 1.2.4.0 (including)