CVE-2024-7481 describes an improper cryptographic signature verification vulnerability in TeamViewer Remote Clients for Windows prior to version 15.58.4, specifically within the TeamViewer_service.exe component. This flaw allows a local unprivileged attacker to elevate privileges and install malicious drivers. The vulnerability carries a high CVSS score of 8.8, indicating a severe impact with local access, low attack complexity, and high confidentiality, integrity, and availability compromise. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TeamViewer | Remote Full Client | >= 11.0.0, < 11.0.259311, >= 12.0.0, < 12.0.259312, >= 13.0.0, < 13.2.36225, >= 14.0.0, < 14.7.48796, >= 15.0.0, < 15.58.4CNA affecteddefault unaffected | |
| TeamViewer | Remote Host | >= 11.0.0, < 11.0.259311, >= 12.0.0, < 12.0.259312, >= 13.0.0, < 13.2.36225, >= 14.0.0, < 14.7.48796, >= 15.0.0, < 15.58.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.