A critical vulnerability has been discovered in the TeamViewer application which allows attackers to remotely gain access to the computer without user’s consent
A critical vulnerability has been discovered in the TeamViewer application which allows attackers to remotely gain access to the computer without user’s consent.TeamViewer is a widely used application having features like desktop sharing, remote control, and file sharing between users.
Read more on: Uber paid $100,000 to Hackers for Not leaking the data!A Github user called Gellin discovered the critical vulnerability in TeamViewer application.According to proof-of-concept (PoC) published by Gellin in GitHub “injectable C++ DLL, that uses naked inline hooking and direct memory modification to change TeamViewer permissions.”By exploiting the vulnerability, the attacker can gain access to the presenter’s or viewer’s session without any permission.If exploited as a presenter attacker will be able to turn on the switch side feature which usually needs the permission of client and change controls and sides, controlling a viewer’s computer.If exploited as a viewer, the attacker will be able to take control over the mouse of presenter’s computer said TJ Nelson, security researcher with Arbor Networks and the ASERT Research team that reviewed the PoC.
Read more on: HP Stealthily installs Spyware without Users ConsentAccording to Threatpost, the vulnerability requires both the viewer and presenter to be first authenticated and then the attacker would inject the PoC code into their own process using tools such as a DLL injector or some type of code mapper.“Once the code is injected into the process it’s programmed to modify the memory values within your own process that enables GUI elements that give you the options to switch control of the session, Once you’ve made the request to switch controls there are no additional check on the server-side before it grants you access,” said Gellin.Teamviewer running on window,macOS and Linux system will be affected by the vulnerability.Teamviewer has confirmed the vulnerability and released a patch for windows on Tuesday. Also said that patch for Linux and macOS versions will be out soon.
You may be interested in reading: India Government Listed 42 Chinese Apps as Spyware and Instructs to Remove them