1. Summary
A vulnerability has been discovered in the TeamViewer Desktop Clients which fail to sanitize filenames supplied by a remote peer before creating files on the receiving endpoint.
2. Vulnerability details
|
CVE-ID |
|
|
Description |
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior to version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.
The vulnerability has been fixed with version 15.81.5 and additional versions listed below. We recommend updating to the latest available version.
At the time of publication, we are not aware of any prior public disclosure of this issue or any indication of exploitation in the wild. |
|
CVSS3.1 Score |
Base Score 7.5 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
3. Affected software and versions
|
Product
|
Versions
|
Info
|
|---|---|---|
|
TeamViewer Full Client (Windows, macOS, Linux) |
< 15.81.5 |
|
|
TeamViewer Host (Windows, macOS, Linux) |
< 15.81.5 |
|
|
TeamViewer QuickSupport (Windows, macOS, Linux) |
< 15.81.5 |
|
Legacy versions
|
Versions
|
Info
|
|---|---|---|
|
TeamViewer Full Client (Windows 7 & 8) |
< 15.64.7 |
|
|
TeamViewer Host (Windows 7 & 8) |
< 15.64.7 |
|
|
TeamViewer QuickSupport (Windows 7 & 8) |
< 15.64.7 |
|
|
TeamViewer Portable (Windows 7 & 8) |
< 15.64.7 |
|
|
TeamViewer Full Client (Windows) v14 |
< 14.7.48833 |
|
|
TeamViewer Full Client (Linux, macOS) v14 |
< 14.7.48838 |
|
|
TeamViewer Host (Windows) v14 |
< 14.7.48833 |
|
|
TeamViewer Host (Linux, macOS) v14 |
< 14.7.48838 |
|
|
TeamViewer QuickSupport (Windows) v14 |
< 14.7.48833 |
|
|
TeamViewer QuickSupport (Linux, macOS) v14 |
< 14.7.48838 |
|
|
TeamViewer Full Client (Windows) v13 |
< 13.2.36229 |
|
|
TeamViewer Full Client (Linux) v13 |
< 13.2.153978 |
|
|
TeamViewer Full Client (macOS) v13 |
< 13.2.153981 |
|
|
TeamViewer Host (Windows) v13 |
< 13.2.36229 |
|
|
TeamViewer Host (Linux) v13 |
< 13.2.153978 |
|
|
TeamViewer Host (macOS) v13 |
< 13.2.153981 |
4. Solutions and mitigations
Update to the latest version (15.81.5 or the latest version available)
5. Acknowledgements
We thank Jamir0quai & sam91281 for the discovery and responsible disclosure via TeamViewer’s Bug Bounty program.