CVE-2021-34803
published 2021-06-16CVE-2021-34803: TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.47%
37.1th percentile
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| teamviewer | teamviewer | < 9.0.259145 | 9.0.259145 |
| teamviewer | teamviewer | >= 10.0.2551 < 10.0.259144 | 10.0.259144 |
| teamviewer | teamviewer | >= 11.0.90968 < 11.0.259143 | 11.0.259143 |
| teamviewer | teamviewer | >= 12.0.92876 < 12.0.259142 | 12.0.259142 |
| teamviewer | teamviewer | >= 13.0.5058 < 13.2.36222 | 13.2.36222 |
| teamviewer | teamviewer | >= 14.0.8346 < 14.2.56678 | 14.2.56678 |
| teamviewer | teamviewer | >= 14.3.4730 < 14.7.48644 | 14.7.48644 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
VISAM VBASE Editor
cisa_ics·2021-11-09·CVSS 7.4
[HIGH] VISAM VBASE Editor
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
VISAM VBASE Editor
Last RevisedNovember 09, 2021
Alert CodeICSA-21-308-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: VISAM
- Equipment: VBASE
- Vulnerabilities: Improper Access Control, Cross-site Scripting, Improper Restriction of XML External Entity Reference, Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow un-neutralized user-controllable data input, disclosure of local files, access to NTLM (Windows New Technology LAN Manager) hashes
GHSA
GHSA-2x34-356c-v9qp: TeamViewer before 14
ghsa_unreviewed·2022-05-24
CVE-2021-34803 [HIGH] CWE-427 GHSA-2x34-356c-v9qp: TeamViewer before 14
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://community.teamviewer.com/English/discussion/111147/windows-v9-0-259145https://community.teamviewer.com/English/discussion/111149/windows-v10-0-259144https://community.teamviewer.com/English/discussion/111150/windows-v11-0-259143https://community.teamviewer.com/English/discussion/111151/windows-v12-0-259142https://community.teamviewer.com/English/discussion/111152/windows-v13-2-36222https://community.teamviewer.com/English/discussion/111153/windows-v14-2-56678https://community.teamviewer.com/English/discussion/111154/windows-v14-7-48644https://community.teamviewer.com/English/discussion/111147/windows-v9-0-259145https://community.teamviewer.com/English/discussion/111149/windows-v10-0-259144https://community.teamviewer.com/English/discussion/111150/windows-v11-0-259143https://community.teamviewer.com/English/discussion/111151/windows-v12-0-259142https://community.teamviewer.com/English/discussion/111152/windows-v13-2-36222https://community.teamviewer.com/English/discussion/111153/windows-v14-2-56678https://community.teamviewer.com/English/discussion/111154/windows-v14-7-48644
2021-06-16
Published