¡¾Îó²îͨ¸æ¡¿TeamViewer í§Òâ´úÂëÖ´ÐÐÎó²î(CVE-2021-34858)

Ðû²¼Ê±¼ä 2021-08-31

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-34858

ʱ      ¼ä

2021-08-24

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥

ÊÇ

ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

TeamViewerÊÇÒ»¸öʹÓÃÆÕ±éµÄÔ¶³Ì¿ØÖÆÈí¼þ£¬£¬£¬Ëü¿ÉÒÔÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ʵÏÖ×ÀÃæ¹²ÏíºÍÎļþ´«Êä¡£¡£¡£¡£¡£¡£¡£

2021Äê8ÔÂ24ÈÕ£¬£¬£¬TeamViewerÐû²¼¸üÐÂͨ¸æ£¬£¬£¬ÐÞ¸´ÁËTeamViewerÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34858£©ºÍÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-34859£©£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë¡¢µ¼Ö¶þ½øÖÆÎļþÍ߽⻣»£»£»òµ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£

TeamViewerí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34858£©

ÓÉÓÚTeamViewerÔÚʹÓÃÏÖÓÐTVS¾ÙÐÐ×°ÖÃʱÈÝÒ×Êܵ½ÎļþÆÊÎöÎÊÌâµÄÓ°Ï죬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë²¢µ¼Ö¶þ½øÖÆÎļþÍ߽⡣¡£¡£¡£¡£¡£¡£µ«Ô¶³ÌʹÓôËÎó²îÐèÒªÓû§½»»¥ÒÔ¼°µÚÈý·½Îó²î¡£¡£¡£¡£¡£¡£¡£

 

TeamViewerÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-34859£©

ÓÉÓÚ¹²ÏíÄÚ´æÖÎÀíÖб£´æÇå¾²ÎÊÌ⣬£¬£¬µ¼ÖÂTeamViewerЧÀÍÖ´ÐÐÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

TeamViewe [Linux] < v15.21.4

TeamViewe [Windows] < v15.21.4

TeamViewe [macOS] < v15.21.2

[½öÏÞ Windows]£ºÄ¬ÈÏÇéÐÎÏ£¬£¬£¬TeamViewer ×°ÖÃÔÚÊܱ£»£»£»£»¤µÄ Program Files Ŀ¼ÖС£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÓÐÒâÑ¡Ôñ½«Æä×°ÖÃÔÚÆäËüλÖ㬣¬£¬Ôò¹¥»÷Õß½«Äܹ»ÊµÏÖȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üе½ÒÔÏÂ×îа汾£º

TeamViewe [Linux] v15.21.4

TeamViewe [Windows] v15.21.6

TeamViewe [macOS] v15.21.2

ÏÂÔØÁ´½Ó£º

https://www.teamviewer.cn/cn/

 

0x03 ²Î¿¼Á´½Ó

https://community.teamviewer.com/English/discussion/117791/linux-v15-21-4

https://community.teamviewer.com/English/categories/change-logs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34858

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-31

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png