#VU22562 Improper control of interaction frequency in TeamViewer Remote Full Client for Windows - CVE-2018-16550
Published: November 6, 2019 / Updated: November 7, 2019
TeamViewer Remote Full Client for Windows
TeamViewer
Description
The vulnerability allows a remote attacker to perform a brute-force attack on the target system.
The vulnerability exists due to the application does not implement sufficient measures to prevent multiple failed authentication attempts. A remote attacker can bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value of the default 4-digit PIN.