Impact
A command injection flaw in the TeamViewer Full Client and Host on Linux allows a remote attacker to run arbitrary commands as the current user when a user clicks a specially crafted URL delivered through the out‑of‑session chat feature. The vulnerability is a classic example of CWE‑78, where improper handling of command‑line arguments leads to injection of malicious commands.
Affected Systems
The flaw applies to all Linux builds of TeamViewer Full Client and Host older than version 15.81.5. Devices running those affected versions are vulnerable as the malicious link can be embedded within chat messages.
Risk and Exploitability
The CVSS score of 8.8 places the issue in the high‑severity range. Exploitation requires user interaction, so it depends on phishing or social engineering. Because the EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of widespread exploitation is uncertain, but the impact of successful exploitation would grant the attacker full control of the target system under the current user context.
OpenCVE Enrichment