#VU22571 Use of Obsolete Function in TeamViewer


Published: 2019-11-07

Vulnerability identifier: #VU22571

Vulnerability risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-477

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
TeamViewer
Client/Desktop applications / Other client software

Vendor: TeamViewer

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of this vulnerability could result in information disclosure, total compromise of the system, and system unavailability.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

TeamViewer: 1.85 - 5.0.8703


External links
http://ics-cert.us-cert.gov/advisories/icsa-19-309-01


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability