LiveActive security incident?Get immediate response
CVE Record

CVE-2021-41380: RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via craf...

RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer application they are using will then hang, until terminated, but no memory leak occurs - the resources are freed once the hung process is terminated and the resource usage is constant during the hang. Only the process that is connected to the fake Server is affected. This is an application bug, not a security issue

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

This CVE describes a RealVNC Viewer hang triggered by a malicious or fake VNC server. The cited description says it affects only the connected Viewer process, requires tricking a user into connecting, and is asserted to be an application bug rather than a security issue.

Executive priority

Treat as low urgency unless RealVNC Viewer 6.21.406 is widely used in workflows involving untrusted VNC connections. The described impact is a single application hang, not system compromise.

Technical view

RealVNC Viewer 6.21.406 can hang when processing crafted RFB protocol data from a remote VNC server. Sources describe denial of service only: no memory leak, constant resource use during the hang, and resources freed after process termination.

Likely exposure

Exposure appears limited to endpoints using RealVNC Viewer 6.21.406 where users can initiate connections to untrusted or fake VNC servers. The source bundle does not identify broader affected versions or server-side products.

Exploitation context

The bundle marks KEV as false and provides no evidence of active exploitation. The cited description says successful triggering requires social engineering a user into connecting to a fake VNC server.

Researcher notes

Evidence is sparse. The CVE text asserts crafted RFB data can hang Viewer but also says this is an application bug, not a security issue. No CVSS, CWE, patch, or affected-version range is provided.

Mitigation direction

  • Check RealVNC guidance and release notes for vendor-supported updates or clarification.
  • Discourage connections to untrusted VNC servers or externally supplied connection targets.
  • Limit VNC Viewer use to approved remote-support workflows and known server addresses.
  • Document response steps for terminating a hung Viewer process safely.

Validation and detection

  • Inventory systems running RealVNC Viewer 6.21.406.
  • Review whether users can connect Viewer to arbitrary external VNC servers.
  • Check helpdesk records for Viewer hangs after connecting to unknown servers.
  • Confirm current vendor classification and remediation guidance before prioritizing deployment work.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-41380 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.