
PoC for CVE-2024-42049
tested on: 2.7.10, 2.8.81; most likely works on all versions where you have 'TightVNC_Service_Control' or 'TightVNC_Application_Control_On_Session_#' pipes accessible on the network.
commands:
notes:
net use \\192.168.42.100\ for example, with a valid account, otherwise it will say [error]: The user name or password is incorrect.; I will add user & password functionality soon to do this automatically...