1 min read

Severe TeamViewer Vulnerability Let Attackers Steal System Password

Silviu STAHIE

August 13, 2020

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Severe TeamViewer Vulnerability Let Attackers Steal System Password

A security researcher found a severe TeamViewer vulnerability affecting Windows versions of the application 8 through 15, allowing attackers to steal system credentials.

TeamViewer is a powerful tool for remote administration, but that also means it’s already a prime target for hackers and other bad actors. Vulnerabilities in TeamViewer are dangerous, and developers have to fix them as quickly as possible.

TeamViewer recently issued a patch covering this severe vulnerability (CVE 2020-13699) as the problem affected a vast array of versions, including many still in operation. When exploited, the vulnerability lets an attacker steal the system password, making it trivial to further compromise the operating system.

“TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: –play URL,” says the CVE advisory. “An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking.”

Bad actors could set up a phishing site with a malicious iframe, which would launch the TeamViewer client when the victim opened the website. What makes the vulnerability especially dangerous is that it would happen with little input from the user.

The developers said the vulnerability doesn’t seem to be actively used in the wild. Now that the exploit’s details are public, though, hackers will most likely make use of it. Since TeamViewer is a popular application, it will take a long time for people to upgrade their clients, allowing attackers to exploit this security issue for quite a while.

The only solution is to update TeamViewer to the latest version as soon as possible.

tags


Author



Right now

Top posts

Enhance your cyber resilience and privacy on Computer Security Day in four easy steps

Enhance your cyber resilience and privacy on Computer Security Day in four easy steps

November 29, 2022

2 min read
How to monitor your online privacy during your Thanksgiving trip

How to monitor your online privacy during your Thanksgiving trip

November 22, 2022

3 min read
Just your yearly dose of Black Friday spam: Cybercrooks get ahead of the game to steal shoppers’ info

Just your yearly dose of Black Friday spam: Cybercrooks get ahead of the game to steal shoppers’ info

November 16, 2022

6 min read
Bitdefender VPN in 2022: the new, the improved, and the soon-to-be

Bitdefender VPN in 2022: the new, the improved, and the soon-to-be

November 14, 2022

5 min read
Cyber Tips for a Spook-Free Halloween

Cyber Tips for a Spook-Free Halloween

October 26, 2022

3 min read
August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August 31, 2022

4 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Hacking cars remotely with just their VIN Hacking cars remotely with just their VIN
Graham CLULEY

December 05, 2022

2 min read
Russian courts attacked by CryWiper malware that poses as ransomware Russian courts attacked by CryWiper malware that poses as ransomware
Graham CLULEY

December 05, 2022

2 min read
Android App in Google Play Store Was Harvesting SMS Messages Helping Criminals Create New Accounts Android App in Google Play Store Was Harvesting SMS Messages Helping Criminals Create New Accounts
Silviu STAHIE

December 02, 2022

1 min read