Junglewise Threat Intelligence

CVE-2019-18988: TeamViewer Desktop Bypass Remote Login Vulnerability

CVE-2019-18988 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2021-11-03

Vendors: Teamviewer.

Executive brief

TeamViewer Desktop uses a shared AES key across all installations for encrypting sensitive configuration data, including the OptionsPasswordAES and, in older versions, the Unattended Access password. An attacker with local access or access to exported registry/configuration files can use this known key to decrypt credentials and bypass remote-login access controls.

Affected products

  • TeamViewer TeamViewer Desktop through 14.7.1965

Timeline

  • 2020-02-07: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog