RealVNC maintains a remote-access and screen-sharing platform centered on its VNC server and viewer products, which are deployed across both consumer and enterprise environments for technical support and system administration. The vendor's vulnerabilities cluster around input-validation and privilege-management weaknesses characteristic of remote-access software, and frequently acquire public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realvnc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4770HIGH The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 throu | Jan 16, 2009 | 10.0 | 27 | NO | NO |
CVE-2022-41975HIGH RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode. | Sep 30, 2022 | 7.8 | 24 | NO | NO |
CVE-2022-27502HIGH RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | Jun 10, 2022 | 7.8 | 24 | NO | NO |
CVE-2008-3493MEDIUM vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet. | Aug 6, 2008 | 5.0 | 24 | NO | YES |
CVE-2021-41380MEDIUM RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires soci | Sep 17, 2021 | 6.5 | 22 | NO | NO |
CVE-2013-6886HIGH RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) vncserver, (2) vncserver-x11, or (3) Xvnc helper. | Dec 28, 2013 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realvnc.
Media articles that mention a CVE ID that affects a product developed by Realvnc — matched by CVE ID, not by vendor name.