- Teamviewer Web online, free
- Teamviewer Web Session
- Teamviewer Online Web
- Teamviewer Us
- Teamviewer Web Online Chat
- Teamviewer Web Store
- Teamviewer Web Login
MS-ISAC ADVISORY NUMBER:
Teamviewer Web online, free
TeamViewer Web Connector lets you control remote computers from any location, with any browser and operating system. TeamViewer is a free solution for Remote Access and Support over the Internet. Please enter your partner's ID in order to control the remote device.
DATE(S) ISSUED:
08/05/2020NEW: Website Monitoring with TeamViewer. Monitor, analyze and improve your website’s uptime, page load speeds and important transactions with TeamViewer Web Monitoring – our new and integrated website monitoring solution. Turn visitors into customers by providing them. The TeamViwer also offers to use it online without downloading the software to your computer. You have to make an account to the TeamViewer website of you don’t have already. After that, you can connect to any device from your TeamViewer online account. The developers have developed this as a TeamViewer online use tool. Remote control Windows, Mac, and Linux computers with TeamViewer: Remote Control within seconds. Provide spontaneous support for friends and family, or access applications on your home computer while on the go. The TeamViewer app allows you to accomplish all of this as if you were sitting right in front of the remote computer.
OVERVIEW:
A vulnerability has been discovered in TeamViewer, which could allow for offline password cracking. TeamViewer is a program used for remote control, desktop sharing, online meetings, web conferencing, and file transfer between systems. Successful exploitation of this vulnerability could allow an attacker to launch TeamViewer with arbitrary parameters. The program could be forced to relay an NTLM authentication request to the attacker’s system allowing for offline rainbow table attacks and brute force cracking attempts. Master of typing 2 v4 4 5. These attacks could lead to further exploitation due to stolen credentials from successful exploitation of this vulnerability.
THREAT INTELLIGENCE:
There are currently no reports of this vulnerability being exploited in the wild.
SYSTEMS AFFECTED:
- TeamViewer versions prior to 15.8.3
RISK:
Government:
- Large and medium government entities: HIGH
- Small government entities: MEDIUM
Businesses:
![Teamviewer Teamviewer](https://www.reitec-software.com/fileadmin/content/products/confit3D/Projektdatenblatt.png)
Teamviewer Web Session
Teamviewer Online Web
- Large and medium business entities: HIGH
- Small business entities: MEDIUM
Home Users:
LOWTECHNICAL SUMMARY:
A vulnerability has been discovered in TeamViewer, which could allow for offline password cracking. Specifically, this vulnerability is due to the program not properly quoting its custom URI handlers. This vulnerability can be exploited when the system visits a maliciously crafted website.
Teamviewer Us
Successful exploitation of this vulnerability could allow an attacker to launch TeamViewer with arbitrary parameters. The program could be forced to relay an NTLM authentication request to the attacker’s system allowing for offline rainbow table attacks and brute force cracking attempts. These attacks could lead to further exploitation due to stolen credentials from successful exploitation of this vulnerability.
RECOMMENDATIONS:
We recommend the following actions be taken:
- Apply appropriate patches from TeamViewer to the vulnerable systems after appropriate testing.
- Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources.
- Inform and educate users regarding threats posed by hypertext links contained in emails or attachments, especially from un-trusted sources.
REFERENCES:
Teamviewer Web Online Chat
CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13699Teamviewer Web Store
Information Hub : Advisories
White paper•16 Oct 2020
Advisory•16 Oct 2020
Teamviewer Web Login
Advisory•16 Oct 2020
Blog post•15 Oct 2020
Copyright © 2020