TeamViewer auth bypass

Several TeamViewer issues have amounted to authentication or authorisation bypass: permission-handling errors that allowed actions the connecting party should not be able to perform, and weaknesses in how the client stored and protected the connection and unattended passwords (so a local attacker recovered them, or the protection was weak enough to defeat). The effect is unauthorised access or elevated action against an affected version without legitimately knowing or guessing the password. Because these are version-specific, fingerprinting the build and matching the advisory is the route, and a recovered stored password additionally enables direct connection and unattended access.

bash
# fingerprint the TeamViewer version (see version detection), then match the advisory
# stored-credential class: recover the connection/unattended password from the client's
#   configuration where its protection is weak/recoverable on a host you can access
reg query 'HKLM\SOFTWARE\WOW6432Node\TeamViewer' 2>nul
# permission/authorisation class: exploit the specific flaw per its advisory

Exploitation notes#

  • Two sub-classes: stored-credential weaknesses (recover the password locally, then connect legitimately, durable via unattended access) and permission/authorisation flaws (act without proper rights against an affected version).
  • The stored-credential path turns brief local access into durable remote access by recovering the unattended password; it overlaps unattended access and depends on the version's storage protection.
  • These are version-specific; fingerprint the build (version detection) and match the advisory for the exact flaw.
  • Where no product flaw applies, the configuration and password attacks remain; this class is the direct-bypass route when the version is vulnerable.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more