1E-2023-2002

Insecure file handling in 1E client for windows

Bulletin ID
1E-2023-2002
Veröffentlicht am
05.10.2023
Letztes Update
02.11.2023
Schweregrad
Wichtig
CVSS
8.8 (High)
Zugewiesene CVE
CVE-2023-45160
Betroffene Produkte
1E Client for Windows

1. Vulnerability Details

CVE-ID

Description

In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. This has been fixed in patch Q23094 as the 1E Client’s temporary directory is now locked down.

CVSS3.1 Score

Base Score 8.8 (High)

CVSS3.1 Vector String

Problem type

2. Affected products and versions

Product Versions

1E Client for Windows

8.1.2.62

1E Client for Windows

8.4.1.159

1E Client for Windows

9.0.1.88

1E Client for Windows

23.7.1.151

Do you want to report a security issue?

TeamViewer’s security team will investigate every submission in our Vulnerability Disclosure Program.