ZeroHour

Vulnerabilities

38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-23568
An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Wind

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be used to bypass ASLR and facilitate further exploitation.

NVD description · AI analysis pending
8.1
group max
<1%
  • teamviewer digital employee experience
CVE-2025-44016
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious ac

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.

NVD description · AI analysis pending
8.8
group max
<1%
  • teamviewer digital employee experience
CVE-2024-6053
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can

Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting.

NVD description · AI analysis pending
4.3<1%
  • teamviewer meeting
  • teamviewer teamviewer
CVE-2024-0819
Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to eleva

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account.

NVD description · AI analysis pending
7.8<1%
  • teamviewer remote
CVE-2023-0837
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged use

An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration.

NVD description · AI analysis pending
5.5<1%
  • teamviewer remote
CVE-2022-23242
TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash.

TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated access to the machine would have allowed to establish a remote connection by reusing the not properly deleted connection password.

NVD description · AI analysis pending
4.2<1%
  • teamviewer teamviewer
CVE-2021-35005
This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer.

This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TeamViewer service. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated array. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-13818.

NVD description · AI analysis pending
3.3<1%
  • teamviewer teamviewer
CVE-2021-34858
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13606.

NVD description · AI analysis pending
7.84%
  • teamviewer teamviewer
CVE-2021-34859
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13697.

NVD description · AI analysis pending
8.89%
  • teamviewer teamviewer
CVE-2021-34803
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

NVD description · AI analysis pending
7.8<1%
  • teamviewer teamviewer
CVE-2020-13699
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers.

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.

NVD description · AI analysis pending
8.826%
  • teamviewer teamviewer
CVE-2019-18988
Hardcoded shared AES key in TeamViewer Desktop enables remote-login password bypass

TeamViewer Desktop through 14.7.1965 encrypts protected settings — including the OptionsPasswordAES value and, in versions before 9.x, the Unattended Access password — with a single AES key shared across all customers' installations since at least v7.0.43148, so anyone who learns that key can decrypt secrets stored in the Windows registry or TeamViewer configuration files. An attacker who already has a session or local access on a system (or who can reach registry/configuration data stored off-machine, such as on a file share or online) can recover the stored credentials and, on pre-9.x versions, the Unattended Access password, gaining remote login and headless file browsing to the system. All TeamViewer Desktop deployments running affected versions through 14.7.1965 are exposed, with the direct remote-login bypass risk greatest on versions before 9.x. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), a public proof-of-concept decryptor is available, and EPSS estimates a 4.7% probability of exploitation within 30 days (91st percentile).

Do: Apply TeamViewer updates per vendor instructions (CISA KEV required action), upgrading installations beyond 14.7.1965 and prioritizing pre-9.x deployments where the Unattended Access password is directly recoverable. Rotate Unattended Access passwords after updating, since credentials encrypted with the shared key may have been decrypted, and avoid storing TeamViewer registry/configuration keys on file shares or online storage. Audit systems with unattended access enabled and review TeamViewer connection logs for anomalous remote logins.

7.05% KEV PoC
  • TeamViewer Desktop through 14.7.1965 (shared AES key present since at least v7.0.43148; Unattended Access password decryptable in versions before 9.x)
massmillions of installations (TeamViewer is one of the most widely deployed remote-access tools, with vendor-reported installs on billions of devices and 600,000+…
CVE-2019-19362
An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows.

An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendor states that it was later fixed.) Upon login, every communication is saved within Windows main memory. When a user logs out or deletes conversation history (but does not exit the application), this data is not wiped from main memory, and therefore could be read by a local user with the same or greater privileges.

NVD description · AI analysis pending
6.52% PoC
  • teamviewer teamviewer
CVE-2019-18251
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.

In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.

NVD description · AI analysis pending
8.82%
  • omron cx-supervisor
  • omron teamviewer
CVE-2019-18196
A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.

A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 13.2.36216), and 14.6.4835 (fixed in 14.7.1965) on Windows could allow an attacker to perform code execution on a target system via a service restart where the DLL was previously installed with administrative privileges. Exploitation requires that an attacker be able to create a new file in the TeamViewer application directory; directory permissions restrict that by default.

NVD description · AI analysis pending
6.7<1%
  • teamviewer teamviewer
CVE-2019-11769
An issue was discovered in TeamViewer 14.2.2558.

An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these credentials are processed in Teamviewer.exe, which allows any application running in the same non-administrative user context to intercept them in cleartext within process memory. By using this technique, a local attacker is able to obtain administrative credentials in order to elevate privileges. This vulnerability can be exploited by injecting code into Teamviewer.exe which intercepts calls to GetWindowTextW and logs the processed credentials.

NVD description · AI analysis pending
7.8<1%
  • teamviewer teamviewer
CVE-2018-16550
TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it

TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value of the default 4-digit PIN.

NVD description · AI analysis pending
9.84%
  • teamviewer teamviewer
CVE-2018-14333
TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might

TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might make it easier for attackers to obtain sensitive information by leveraging an unattended workstation on which TeamViewer has disconnected but remains running.

NVD description · AI analysis pending
8.13% PoC
  • teamviewer teamviewer