


Perceptive Security
SOC/SIEM Consultancy

UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 19:17:24
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access
UltraVNC versions through 1.8.2.2 contain a critical cryptographic weakness in the MS-Logon II authentication scheme. The Diffie-Hellman key exchange uses only 64-bit parameters, which can be broken by Pollard's rho algorithm in under one second on modern hardware. The private exponent is generated using a weak RNG based on three libc rand() calls seeded with time(NULL), providing only ~31 bits of entropy and making it recoverable in under a minute. A passive network attacker who can observe the MS-Logon II handshake can derive the shared DH key and decrypt transmitted credentials. This results in full username and password disclosure to any attacker capable of sniffing, recording, or performing a man-in-the-middle attack on the connection. Only the legacy MS-Logon II scheme is affected; the newer MS-Logon III using X25519 and AES-256-GCM is not vulnerable. Users are advised to migrate to MS-Logon III or apply available patches.
Technical details
Mitigation steps:
Affected products:
UltraVNC 1.8.2.2 and earlier
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
