← Browse

CVE-2019-18988

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
4.7%
91.4th percentile
CISA KEV
Listed
Added 2021-11-03 · patch by 2022-05-03
Weakness / dates
Published — · modified —

Timeline

Description

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).

Official: NVD · CVE.org