A command injection vulnerability exists in TeamViewer Full Client and Host for Linux prior to version 15.81.5. A remote attacker can exploit this vulnerability by sending a specially crafted URL through the out-of-session chat feature, which requires user interaction to execute arbitrary commands in the context of the current user. This vulnerability has significant implications for users of TeamViewer F [truncated]
A broken access control vulnerability exists in the TeamViewer DEX Platform (On-Premises) prior to version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher-privileged roles. This vulnerability allows an attacker with low-privileged credentials to gain unautho [truncated]
CVE-2019-18988 is a TeamViewer Desktop vulnerability described as a bypass of remote login. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which means it is treated as a known-exploited issue and should be prioritized for remediation. The supplied corpus does not include a CVSS score or version-specific impact details, so the safest response is to follow vendor update guidance [truncated]