discovered 03 Aug 2026
CVE-2022-27502
→ View on GitHubCVE-2022-27502 is a DLL hijacking exploit targeting RealVNC Server versions up to 6.9.0, allowing for arbitrary command execution by leveraging a vulnerable installation process. The tool enables users to execute any command through a crafted DLL that captures the output in a specified output file. Notable features include the ability to modify the executed command by editing specific code lines and recompiling the DLL.