CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-13699

HIGH
8.8
CVSS Severity Score
EPSS Score0.1450%
EPSS Percentile25.84th
Published2020年7月29日
Last Modified2024年11月21日

Vulnerability Description

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.

Affected Platforms (CPE)

📦
Teamviewer

Teamviewer

< 15.8.3

References & Advisories

相關漏洞威脅