Impact
A vulnerability exists in the Connection State Management module of TeamSpeak 3 Server, where an attacker can trigger a use‑after‑free by manipulating the process_resend_queue function. The flaw can lead to a crash of the server or, in some circumstances, may allow the attacker to read unintended memory contents. No evidence of arbitrary code execution is reported. The weakness aligns with CWE-416 use‑after‑free and CWE-119 unsafe memory handling.
Affected Systems
The flaw affects TeamSpeak 3 Server releases up to and including 3.13.7. All installations running those versions are vulnerable, regardless of environment configuration. The relevant component is the connection state management service distributed by TeamSpeak.
Risk and Exploitability
The issue receives a CVSS score of 5.3, indicating moderate severity. An external attacker can exercise the vulnerable code over the network; however, no exploit code and exploit probability are available in EPSS, and the vulnerability is not listed in CISA's KEV catalog. Because the attack vector is remote and requires network access, limiting client connectivity further mitigates risk until a patch is applied.
OpenCVE Enrichment