FAIL › dossier
TeamViewer
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 1
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2019-18988 | high | TeamViewer Desktop reused a single AES key across customer installations, allowing attackers to decrypt registry/config files and bypass remote-login controls. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows bypass of remote-login access control via shared AES key, enabling decryption of protected info and unattended access passwords; widely tracked as exploited.
NVD describes critical bypass of remote-login access control via shared AES key, allowing decryption of protected info and unattended access passwords.
"TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system)."
Neutral CVE database listing; no sentiment toward vendor.
Neutral NVD page; no sentiment toward vendor.
Neutral KEV catalog listing; no sentiment toward vendor.
Neutral CVE search page; no sentiment toward vendor.
Neutral Vulnerability tracking page; no sentiment toward vendor.
Neutral Radio site; no sentiment toward vendor.