¡¾Â©¶´Í¨¸æ¡¿TeamViewer ÈÎÒâ´úÂëÖ´ÐЩ¶´(CVE-2021-34858)

Ðû²¼Ê±¼ä 2021-08-31

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-34858

ʱ      ¼ä

2021-08-24

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥

ÊÇ

ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

 

TeamViewerÊÇÒ»¸öʹÓù㷺µÄÔ¶³Ì¿ØÖÆÈí¼þ £¬Ëü¿ÉÒÔÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ʵÏÖ×ÀÃæ¹²ÏíºÍÎļþ´«Êä¡£

2021Äê8ÔÂ24ÈÕ £¬TeamViewerÐû²¼¸üÐÂͨ¸æ £¬ÐÞ¸´ÁËTeamViewerÖеÄÒ»¸öÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-34858£©ºÍÒ»¸öÔ½½ç¶Áȡ©¶´£¨CVE-2021-34859£© £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ö´ÐÐÈÎÒâ´úÂë¡¢µ¼Ö¶þ½øÖÆÎļþ±ÀÀ£»òµ¼ÖÂÔ½½ç¶ÁÈ¡¡£

TeamViewerÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-34858£©

ÓÉÓÚTeamViewerÔÚʹÓÃÏÖÓÐTVS½øÐа²×°Ê±ÈÝÒ×Êܵ½Îļþ½âÎöÎÊÌâµÄÓ°Ïì £¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ö´ÐÐÈÎÒâ´úÂë²¢µ¼Ö¶þ½øÖÆÎļþÍ߽⡣µ«Ô¶³ÌÀûÓôË©¶´ÐèÒªÓû§½»»¥ÒÔ¼°µÚÈý·½Â©¶´¡£

 

TeamViewerÔ½½ç¶Áȡ©¶´£¨CVE-2021-34859£©

ÓÉÓÚ¹²ÏíÄÚ´æ¹ÜÀíÖдæÔÚÄþ¾²ÎÊÌâ £¬µ¼ÖÂTeamViewer·þÎñÖ´ÐÐÔ½½ç¶ÁÈ¡¡£

 

Ó°Ï췶Χ

TeamViewe [Linux] < v15.21.4

TeamViewe [Windows] < v15.21.4

TeamViewe [macOS] < v15.21.2

[½öÏÞ Windows]£ºÄ¬ÈÏÇé¿öÏ £¬TeamViewer °²×°ÔÚÊܱ£»¤µÄ Program Files Ŀ¼ÖС£Èç¹ûÓû§ÓÐÒâÑ¡Ôñ½«Æä°²×°ÔÚÆäËüλÖà £¬Ôò¹¥»÷Õß½«Äܹ»ÊµÏÖȨÏÞÌáÉý¡£

 

0x02 ´¦Öý¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´ £¬½¨Ò鼰ʱÉý¼¶¸üе½ÒÔÏÂ×îа汾£º

TeamViewe [Linux] v15.21.4

TeamViewe [Windows] v15.21.6

TeamViewe [macOS] v15.21.2

ÏÂÔØÁ´½Ó£º

https://www.teamviewer.cn/cn/

 

0x03 ²Î¿¼Á´½Ó

https://community.teamviewer.com/English/discussion/117791/linux-v15-21-4

https://community.teamviewer.com/English/categories/change-logs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34858

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-31

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png