Skip to content
COOEY

EXPOSURES › CVE-2019-18988

CVE-2019-18988

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-18988 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatched

TeamViewer Desktop reused a single AES key across customer installations, allowing attackers to decrypt registry/config files and bypass remote-login controls.

The vendor reused a single AES key for different customers, enabling decryption of protected data and bypass of remote-login access controls. DIB orgs must ensure unique cryptographic keys per customer and monitor for reused keys in third-party tools. This is an unpatched, actively exploited vulnerability that demonstrates severe negligence in cryptographic design.

Shame score — Reusing a single AES key across different customers is a fundamental cryptographic failure that directly enables data decryption and access control bypass, representing a severe, avoidable design flaw.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows bypass of remote-login access control via shared AES key, enabling decryption of protected info and unattended access passwords; widely tracked as exploited.
cooey ↗ severe-fallout -0.80
NVD describes critical bypass of remote-login access control via shared AES key, allowing decryption of protected info and unattended access passwords.
"TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system)."
www.cvefind.com ↗ severe-fallout +0.00
Neutral CVE database listing; no sentiment toward vendor.
NVD ↗ severe-fallout +0.00
Neutral NVD page; no sentiment toward vendor.
cvefeed.io ↗ severe-fallout +0.00
Neutral KEV catalog listing; no sentiment toward vendor.
app.opencve.io ↗ severe-fallout +0.00
Neutral CVE search page; no sentiment toward vendor.
cyber.trackr.live ↗ severe-fallout +0.00
Neutral Vulnerability tracking page; no sentiment toward vendor.
www.boz.radio ↗ severe-fallout +0.00
Neutral Radio site; no sentiment toward vendor.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.