QID 379426
Date Published: 2024-03-18
QID 379426: TeamViewer Improper initialization of Default Settings Vulnerability (TV-2024-1001)
TeamViewer is a computer software package for remote control, desktop sharing, and file transfer between computers.
In the Teamviewer Client, access to the personal password setting doesnot require administrative rights. A low privileged user on a multi-user system, with access to the client, can set a personal password. That potentially allows an unprivileged user to establish a remote connection to other currently logged-in users on the same system
Affected Versions:
TeamViewer Remote Client prior to Version 15.51.5
QID Detection Logic (Authenticated):
(Windows) The QID checks for the TeamViewer\InstallationDirectory and Classes\TeamViewerConfiguration\DefaultIcon to check the vulnerable version of TeamViewer.exe.
QID Detection Logic (Authenticated):
(Mac) TeamViewer.app to check the vulnerable version of the product.
Improper initialization of default settings may allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account.
CVEs related to QID 379426
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TV-2024-1001 |
|