CVE-2024-7479 describes a critical privilege escalation vulnerability in TeamViewer Remote Clients for Windows prior to version 15.58.4. An attacker with local unprivileged access can exploit an improper cryptographic signature verification during VPN driver installation to elevate privileges and install malicious drivers. This vulnerability carries a high CVSS score of 8.8, indicating significant impact with high confidentiality, integrity, and availability concerns, and a low attack complexity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the FAUCET Risk Score of 80/100 highlights its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TeamViewer | Remote Full Client | >= 11.0.0, < 11.0.259311, >= 12.0.0, < 12.0.259312, >= 13.0.0, < 13.2.36225, >= 14.0.0, < 14.7.48796, >= 15.0.0, < 15.58.4CNA affecteddefault unaffected | |
| TeamViewer | Remote Host | >= 11.0.0, < 11.0.259311, >= 12.0.0, < 12.0.259312, >= 13.0.0, < 13.2.36225, >= 14.0.0, < 14.7.48796, >= 15.0.0, < 15.58.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.