CVE-2019-18988
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer.
Read full descriptionShow less
With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.71%
- Percentile among all scored CVEs: 92
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 11/3/2021
- Remediation due date: 5/3/2022
- Known ransomware use: Unknown
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Proof of concept on GitHub (unverified) · List of proofs of concept on GitHub
⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Primary impact
T1078.003Local Accountsstealth · persistence · privilege escalation · initial access70 % - Secondary impact
T1021.005VNClateral movement65 % - Secondary impact
T1552.001Credentials In Filescredential access75 %
CVE-2019-18988 explota una clave AES compartida en TeamViewer (CWE-521: almacenamiento débil de contraseña) permitiendo descifrar credenciales de acceso remoto desatendido. AV:L con PR:L confirma escalada local. Impactos: acceso a cuenta (T1078.003), credenciales en almacenamiento (T1552.001), acces
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-521
- CWE-521
References
- https://community.teamviewer.com/t5/Announcements/Specification-on-CVE-2019-18988/td-p/82264
- https://community.teamviewer.com/t5/Knowledge-Base/tkb-p/Knowledgebase?threadtype=label&labels=Security
- https://twitter.com/Blurbdust/status/1224212682594770946?s=20
- https://whynotsecurity.com/blog/teamviewer/
- https://community.teamviewer.com/t5/Announcements/Specification-on-CVE-2019-18988/td-p/82264
- https://community.teamviewer.com/t5/Knowledge-Base/tkb-p/Knowledgebase?threadtype=label&labels=Security
- https://twitter.com/Blurbdust/status/1224212682594770946?s=20
- https://whynotsecurity.com/blog/teamviewer/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-18988
Raw JSON (NVD)
Show
{
"id": "CVE-2019-18988",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2019-18988",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-04T20:33:26.822954Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-02-07T16:15:10.033",
"references": [
{
"url": "https://community.teamviewer.com/t5/Announcements/Specification-on-CVE-2019-18988/td-p/82264",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://community.teamviewer.com/t5/Knowledge-Base/tkb-p/Knowledgebase?threadtype=label&labels=Security",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://twitter.com/Blurbdust/status/1224212682594770946?s=20",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://whynotsecurity.com/blog/teamviewer/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://community.teamviewer.com/t5/Announcements/Specification-on-CVE-2019-18988/td-p/82264",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://community.teamviewer.com/t5/Knowledge-Base/tkb-p/Knowledgebase?threadtype=label&labels=Security",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/Blurbdust/status/1224212682594770946?s=20",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://whynotsecurity.com/blog/teamviewer/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-18988",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-521"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-521"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system."
},
{
"lang": "es",
"value": "TeamViewer Desktop versiones hasta 14.7.1965, permite omitir el control de acceso del inicio de sesión remoto porque la misma clave es usada para las instalaciones de diferentes clientes. Usó una clave AES compartida para todas las instalaciones a partir, de al menos, hasta la versión v7.0.43148, y la usó para al menos OptionsPasswordAES en la versión actual del producto. Si un atacante fuese conocido esta clave, podría descifrar la información de protección almacenada en el registro o en los archivos de configuración de TeamViewer. Con versiones anteriores a v9.x, esto permitía a atacantes descifrar la contraseña de Unattended Access en el sistema (que permite el inicio de sesión remoto en el sistema, así como la exploración de archivos sin encabezado). La última versión aún utiliza la misma clave para OptionPasswordAES pero parece haber cambiado la manera en que se almacena la contraseña de Unattended Access. Mientras que en la mayoría de los casos un atacante requiere una sesión existente en un sistema, si las claves de registro/configuración fueron almacenadas fuera de la máquina (como en un recurso compartido de archivos o en línea), un atacante podría descifrar la contraseña requerida para iniciar sesión en el sistema ."
}
],
"lastModified": "2026-06-17T02:25:42.777",
"cisaActionDue": "2022-05-03",
"cisaExploitAdd": "2021-11-03",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:teamviewer:teamviewer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1169616E-3D16-4688-8402-8E922F26B339",
"versionEndIncluding": "14.7.1965"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "TeamViewer Desktop Bypass Remote Login Vulnerability"
}