CVE-2019-18988: TeamViewer Desktop
EPSS4.7%No. 1429 of 1739 in KEV
CVE year2019~2 yrs before listing
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | TeamViewer |
| Product | Desktop |
| Name | TeamViewer Desktop Bypass Remote Login Vulnerability |
| Added to KEV | 2021-11-03 |
| US federal due date | 2022-05-03 |
| Ransomware use | Unknown |
| CWE | CWE-521 |
CISA description
TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A TeamViewer Desktop vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.