Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m856-89mj-r6pg

Опубликовано: 01 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.

EPSS

Процентиль: 6%
0.00025
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 4.7
nvd
4 месяца назад

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.

CVSS3: 4.7
fstec
4 месяца назад

Уязвимость программного обеспечения для удалённого управления компьютером TeamViewer, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 6%
0.00025
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-59