#VU35040 Input validation error in TeamViewer Remote Full Client for Windows - CVE-2019-18251

 

#VU35040 Input validation error in TeamViewer Remote Full Client for Windows - CVE-2019-18251

Published: November 26, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35040
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2019-18251
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
TeamViewer Remote Full Client for Windows
Software vendor:
TeamViewer

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.


Remediation

Install update from vendor's website.

External links