EXPOSURES › CVE-2019-18988
CVE-2019-18988
HIGH ⌖ ON CISA KEV · EXPLOITEDTeamViewer Desktop reused a single AES key across customer installations, allowing attackers to decrypt registry/config files and bypass remote-login controls.
The vendor reused a single AES key for different customers, enabling decryption of protected data and bypass of remote-login access controls. DIB orgs must ensure unique cryptographic keys per customer and monitor for reused keys in third-party tools. This is an unpatched, actively exploited vulnerability that demonstrates severe negligence in cryptographic design.
Shame score — Reusing a single AES key across different customers is a fundamental cryptographic failure that directly enables data decryption and access control bypass, representing a severe, avoidable design flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
"TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system)."