¡¾·ì϶¹«¸æ¡¿TeamViewer ËÁÒâ´úÂëÖ´Ðзì϶(CVE-2021-34858)

°ä²¼¹¦·ò 2021-08-31

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-34858

ʱ      ¼ä

2021-08-24

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥

ÊÇ

ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

TeamViewerÊÇÒ»¸öʹÓÃ¿í·ºµÄÔ¶³Ì½ÚÔìÈí¼þ£¬ËüÄܹ»ÔÚÖ°ºÎ·À»ðǽºÍNAT´úÀíµÄºó¶ÜʵÏÖ×ÀÃæ¹²ÏíºÍÎļþ´«Êä¡£

2021Äê8ÔÂ24ÈÕ£¬TeamViewer°ä²¼¸üв¼¸æ£¬½¨¸´ÁËTeamViewerÖеÄÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-34858£©ºÍÒ»¸öÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-34859£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë¡¢µ¼Ö¶þ½øÔìÎļþ±ÀÀ£»òµ¼ÖÂÔ½½ç¶ÁÈ¡¡£

TeamViewerËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-34858£©

ÓÉÓÚTeamViewerÔÚʹÓÃÏÖÓÐTVS½øÐÐ×°ÖÃʱÈÝÒ×Êܵ½Îļþ½âÎöÎÊÌâµÄÓ°Ï죬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ִÐÐËÁÒâ´úÂë²¢µ¼Ö¶þ½øÔìÎļþ±ÀÀ£¡£µ«Ô¶³ÌÀûÓô˷ì϶±ØÒªÓû§½»»¥ÒÔ¼°µÚÈý·½·ì϶¡£

 

TeamViewerÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-34859£©

ÓÉÓÚ¹²ÏíÄÚ´æÖÎÀíÖдæÔÚ°²È«ÎÊÌ⣬µ¼ÖÂTeamViewer·þÎñÖ´ÐÐÔ½½ç¶ÁÈ¡¡£

 

Ó°ÏìÁìÓò

TeamViewe [Linux] < v15.21.4

TeamViewe [Windows] < v15.21.4

TeamViewe [macOS] < v15.21.2

[½öÏÞ Windows]£ºÄ¬ÈÏÇé¿öÏ£¬TeamViewer ×°ÖÃÔÚÊܱ£»¤µÄ Program Files Ŀ¼ÖС£ÈôÊÇÓû§ÓÐÒâÑ¡Ôñ½«Æä×°ÖÃÔÚÆäËüµØÎ»£¬Ôò¹¥»÷Õß½«¿ÉÄÜʵÏÖȨÏÞÌáÉý¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬½¨ÒéʵʱÉý¼¶¸üе½ÒÔÏÂ×îа汾£º

TeamViewe [Linux] v15.21.4

TeamViewe [Windows] v15.21.6

TeamViewe [macOS] v15.21.2

ÏÂÔØÁ´½Ó£º

https://www.teamviewer.cn/cn/

 

0x03 ²Î¿¼Á´½Ó

https://community.teamviewer.com/English/discussion/117791/linux-v15-21-4

https://community.teamviewer.com/English/categories/change-logs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34858

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-31

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png