Impact
An improper access control flaw allows an authenticated remote attacker to modify the access parameters that a user has explicitly denied. By altering these settings during a session start, the attacker can invoke functionality that was meant to be restricted, potentially leading to remote execution of arbitrary code. The weakness is a classic authorization bypass identified as CWE-284.
Affected Systems
TeamViewer Full Client and Host on Windows, Linux, and macOS are affected. No specific vendor version numbers are listed; any installed instance that has not been updated to the latest release may be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high risk, and EPSS data is unavailable. It is not currently listed in the CISA KEV catalog. Successful exploitation requires the attacker to first authenticate and then manipulate session parameters, so the attack vector is inbound remote within an established TeamViewer connection.
OpenCVE Enrichment