在 Linux 版的 TeamViewer 完整客户端和主机版本(低于 15.81.5 版本)中,存在一个命令注入漏洞。攻击者可以通过发送一个经过精心构造的 URL,利用会话外聊天功能,在当前用户权限上下文中执行任意命令。漏洞的利用需要用户交互,即用户需要点击恶意链接。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TeamViewer | Full Client | 15.0< 15.81.5 |
affected |
14.0< 14.7.488838 |
affected | ||
13.0< 13.2.153978 |
affected | ||
| TeamViewer | Host | 15.0< 15.81.5 |
affected |
14.0< 14.7.488838 |
affected | ||
13.0< 13.2.153978 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TeamViewer | Full Client | 15.0 ~ 15.81.5 | - |
|
| TeamViewer | Host | 15.0 ~ 15.81.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet