Get up to date Tech &Security related news and books to become a Hacker

Breaking

Thursday, December 7, 2017

New TeamViewer Hack Could Allow Clients to Hijack Viewers' Computer





If yes, then you should pay attention to a critical vulnerability discovered in the software that could allow users sharing a desktop session to gain complete control of the other's PC without permission.

TeamViewer is a popular remote-support software that lets you securely share your desktop or take full control of other's PC over the Internet from anywhere in the world.



TeamViewer Hack Could Be Used By Anyone—Server Or Client


Gellin has also published a proof-of-concept (PoC) code, which is an injectable C++ DLL, which leverages "naked inline hooking and direct memory modification to change TeamViewer permissions."

The injectable C++ DLL (hack) can be used by both, the client and the server, which results as mentioned below:

If exploited by the Server—the hack allows viewers to enable "switch sides" feature, which is only active after the server authenticated control with the client, eventually allowing the server to initiate a change of control/sides.









A TeamViewer spokesperson told The Hacker News, "We are patching versions 11-13. Windows is already available, whereas MacOS and Linux are expected later today."
TeamViewer users are recommended to install the patched versions of the software as soon as they become available. Patches will be delivered automatically to those users who have configured their TeamViewer software to receive automatic updates.  

No comments:

Post a Comment