Description Preview
Overview
This CVE describes a local vulnerability in TeamViewer Desktop that arises from using a single shared AES key across installations to protect sensitive credentials. The risk is that an attacker who acquires the key can decrypt credentials stored on the host (registry or config files) and potentially bypass remote-login controls. The issue historically allowed decrypting the Unattended Access password in older versions, enabling remote access and file browsing; although newer storage methods may mitigate some exposure, the shared-key problem persists for certain credentials (OptionsPasswordAES). The CVSS context indicates a base score of 7.0 (HIGH) with local attack vector, high impact to confidentiality, integrity, and availability, low privileges required, and no user interaction. In practice, exploitation is more likely when credentials are stored off-device, such as on network shares or in online storage.
Remediation
- Apply the latest TeamViewer release and follow the vendor’s security advisories for CVE-2019-18988. Ensure all affected endpoints are updated to a version that addresses the issue.
- If immediate patching isn’t possible, disable Unattended Access or require interactive authentication for remote login to minimize credential exposure.
- Audit and secure credential storage: ensure registry/config data containing passwords is not stored on network shares or insecure locations; move credentials to a secure, access-controlled vault or disable storing sensitive passwords locally if feasible.
- Enforce stronger authentication: enable two-factor authentication for TeamViewer accounts and require strong, regularly rotated passwords.
- Restrict remote access exposure: limit remote-login capabilities to trusted networks and monitor access logs for suspicious activity; disable remote login when not needed.
- Perform asset discovery and inventory to identify endpoints still on vulnerable versions and prioritize upgrades.
- Establish a policy to manage per-installation credentials (if available) rather than shared keys, and review any vendor guidance on mitigating OptionsPasswordAES exposure.
References
- https://community.teamviewer.com/t5/Knowledge-Base/tkb-p/Knowledgebase?threadtype=label&labels=Security
- https://whynotsecurity.com/blog/teamviewer/
- https://twitter.com/Blurbdust/status/1224212682594770946?s=20
- https://community.teamviewer.com/t5/Announcements/Specification-on-CVE-2019-18988/td-p/82264
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Public AdministrationPublic Administration: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- Educational ServicesEducational Services: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Finance and InsuranceFinance and Insurance: Low
- InformationInformation: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Retail TradeRetail Trade: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- ConstructionConstruction: Low
- MiningMining: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low

