CVE-2026-3787 | UltraVNC 1.6.4.0 on Windows Windows Service cryptbase.dll uncontrolled search path (EUVD-2026-10277)
A vulnerability was found in UltraVNC 1.6.4.0 on Windows. It has been classified as problematic. This affects an unknown function in the library cryptbase.dll of the component Windows Service. This manipulation causes uncontrolled search path.
This vulnerability appears as CVE-2026-3787. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.