Unsecured Symlink in Prior Version of TeamViewer Remote Client Allows for Elevated Privileges or Denial of Service
CVE-2024-1933

7.1HIGH

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
26 March 2024

Badges

📰 News Worthy

What is CVE-2024-1933?

Summary: CVE-2024-1933 is a security vulnerability in the TeamViewer Remote Client prior version 15.52 for macOS that allows attackers to potentially elevate privileges or conduct a denial-of-service attack by overwriting the symlink. The vulnerability affects macOS users of older versions of TeamViewer, and the potential consequences include privilege escalation, data theft, and system disruption. TeamViewer has released version 15.52 to fix the vulnerability and urges users to update immediately to mitigate the risk. There are no known exploitations by ransomware groups at this time.

Affected Version(s)

Remote Client MacOS 0 < 15.52

News Articles

TheCyberThrone Security Week In Review – March 30, 2024

Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the week ending Saturday, March 30, 2024 TeamViewer Vulnerability Affecting macOS -CVE-2024-1933 A security vulnerability in TeamViewer has been uncovered, putting mac...

TeamViewer Archives

VulnerabilityMarch 26, 2024CVE-2024-1933: TeamViewer Bug Exposes macOS Users: Update Immediately!A security vulnerability in TeamViewer has been uncovered, putting macOS users of older versions at significant...

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by securityonline.info

  • Vulnerability published

  • Vulnerability Reserved

.