We would like to show you a description here but the site won’t allow us. Now available team viewer on your web browser, it's called web-connector. You don't need to download software. Simply access your client pc through your web. Then when you login to teamviewer and hit connect, you'll get the option to (install extension, install desktop app, or use webclient). It's a little unclear because the web client doesn't look like a link, but hover over the work 'web client' and click it, then you'll be able to connect.
MS-ISAC ADVISORY NUMBER:
2020-106To allow the proper functionality of our website and to improve your experience, TeamViewer and its partners would like to place cookies (and similar technologies, “Cookies”) on your device. This way we can provide the best possible performance of our services, as well as analyze the usage and subsequently optimize our marketing efforts.
DATE(S) ISSUED:
08/05/2020OVERVIEW:
Roadblock 1 5 9 – content blocker ace inhibitor. A vulnerability has been discovered in TeamViewer, which could allow for offline password cracking. TeamViewer is a program used for remote control, desktop sharing, online meetings, web conferencing, and file transfer between systems. Successful exploitation of this vulnerability could allow an attacker to launch TeamViewer with arbitrary parameters. The program could be forced to relay an NTLM authentication request to the attacker’s system allowing for offline rainbow table attacks and brute force cracking attempts. These attacks could lead to further exploitation due to stolen credentials from successful exploitation of this vulnerability.
THREAT INTELLIGENCE:
There are currently no reports of this vulnerability being exploited in the wild.
SYSTEMS AFFECTED:
- TeamViewer versions prior to 15.8.3
RISK:
Government:
- Large and medium government entities: HIGH
- Small government entities: MEDIUM
Teamviewer Web Connector
Businesses:
Teamviewer Web Support
- Large and medium business entities: HIGH
- Small business entities: MEDIUM
Home Users:
LOWTECHNICAL SUMMARY:
A vulnerability has been discovered in TeamViewer, which could allow for offline password cracking. Specifically, this vulnerability is due to the program not properly quoting its custom URI handlers. This vulnerability can be exploited when the system visits a maliciously crafted website.
Successful exploitation of this vulnerability could allow an attacker to launch TeamViewer with arbitrary parameters. The program could be forced to relay an NTLM authentication request to the attacker’s system allowing for offline rainbow table attacks and brute force cracking attempts. These attacks could lead to further exploitation due to stolen credentials from successful exploitation of this vulnerability.
RECOMMENDATIONS:
We recommend the following actions be taken:
- Apply appropriate patches from TeamViewer to the vulnerable systems after appropriate testing.
- Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources.
- Inform and educate users regarding threats posed by hypertext links contained in emails or attachments, especially from un-trusted sources.
REFERENCES:
CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13699Information Hub : Advisories
White paper•16 Oct 2020
Advisory•16 Oct 2020
Advisory•16 Oct 2020
Blog post•15 Oct 2020
![Teamviewer online web free Teamviewer online web free](https://www.addison.de/uploads/pics/WKD-ADD_ABB_1527_Deutschlandkarte_WEB.jpg)
Copyright © 2020