Remote Code Execution Vulnerability in TeamViewer Software
CVE-2021-34858

7.8HIGH

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
13 January 2022

What is CVE-2021-34858?

This vulnerability impacts installations of TeamViewer, enabling remote attackers to execute arbitrary code if a user visits a compromised webpage or opens a malicious file. The flaw is located in the parsing of TVS files, arising from inadequate validation of user-supplied input. This oversight can lead to reading beyond the end of an allocated data structure, allowing an attacker to execute code within the context of the affected process. System administrators should apply available security patches promptly to mitigate potential exploitation.

Affected Version(s)

TeamViewer 15.16.8.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kdot
.