Vulnerability identifier: #VU22571
Vulnerability risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-477
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
TeamViewer
Client/Desktop applications /
Other client software
Vendor: TeamViewer
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability could result in information disclosure, total compromise of the system, and system unavailability.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
TeamViewer: 1.85 - 5.0.8703
External links
http://ics-cert.us-cert.gov/advisories/icsa-19-309-01
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.