Command Injection in TeamViewer Desktop Client for Linux through Chat Link Handling
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.8epss 2.0%
probabilidade de exploração
2.0%top 20% das CVEs
exploração observada
nãonenhuma fonte reporta
A command injection vulnerability in TeamViewer Full
Client and Host for Linux prior to version 15.81.5 allows a remote attacker to
execute arbitrary commands in the context of the current user via a specially
crafted URL sent through the out-of-session chat feature. Exploitation requires
user interaction by clicking the malicious link.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H