Use of Obsolete Function in TeamViewer Remote Full Client for Windows - #VU22571

 

Use of Obsolete Function in TeamViewer Remote Full Client for Windows - #VU22571

Published: November 7, 2019


Vulnerability identifier: #VU22571
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-477
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of this vulnerability could result in information disclosure, total compromise of the system, and system unavailability.


Affected software

TeamViewer Remote Full Client for Windows
CX-Supervisor

Remediation

Install updates from vendor's website.

CX-Supervisor - update to 3.5.1

External References

Related Security Bulletins