1. Summary
A vulnerability has been discovered in the TeamViewer Client for Linux which allows Remote Code Execution via Chat.
2. Vulnerability details
3. Affected software and versions
4. Solutions and mitigations
- Update to the latest version (15.81.5 or the latest version available)
- As a temporary mitigation, if an immediate update is not feasible, users are advised not to click any links received via chat in affected TeamViewer clients.
5. Acknowledgements
We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure via TeamViewer’s Bug Bounty program.