Impact
A heap-based buffer overflow vulnerability exists in the ECC Key Parser component of TeamSpeak 3 Server. The flaw can be exploited with remote traffic and could allow an attacker to overwrite heap data, potentially leading to execution of arbitrary code or denial of service. The weakness is a classic example of incorrect bounds checking, classified under CWE-119 and CWE-122.
Affected Systems
The vulnerability affects TeamSpeak 3 Server versions up to 3.13.7. The specific component affected is the ECC Key Parser. Users running any pre‑3.13.8 installation are exposed. No additional product or version listings are reported by the CNA.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. Since EPSS is not available and the vulnerability is not listed in CISA KEV, there is no public evidence of active exploitation, yet the ability to trigger a heap overflow remotely raises a non‑trivial risk. Attackers would need to supply crafted ECC key data to the server, implying a remote network attack vector. Ensuring that the server never accepts untrusted node key data and applying the fix mitigates the risk.
OpenCVE Enrichment