CVE-2019-18988

HIGH(7.0)KEV

TeamViewer Desktop Bypass Remote Login Vulnerability

Description

CVE-2019-18988 is a high-severity vulnerability in TeamViewer Desktop through version 14.7.1965 that allows bypass of remote-login access control due to the use of a shared AES encryption key across all installations. Since at least version 7.0.43148, TeamViewer has used the same AES key for encrypting sensitive data such as the OptionsPasswordAES value stored in the Windows registry or configuration files. An attacker who knows this key can decrypt protected information, and in versions prior to 9.x, could recover the Unattended Access password to gain remote login access. CISA has added CVE-2019-18988 to the Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 8.8% (92.4th percentile) indicates a notable probability of exploitation.

KEV Information

Vendor
TeamViewer
Product
Desktop
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
teamviewerteamviewer<= 14.7.1965

Multiple CVSS Assessments

Source: [email protected](Primary)
7.0
HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.0
HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-521: Weak Password Requirements

Weak Password Requirements refers to insufficient credential protection mechanisms that fail to adequately safeguard authentication data. In the case of TeamViewer Desktop, the use of a single shared AES encryption key across all installations worldwide constitutes a fundamental cryptographic weakness, as knowledge of this key allows any attacker to decrypt credentials and sensitive configuration data stored on any TeamViewer installation.

Learn more: CWE-521 — Weak Password Requirements

Impact Analysis

CVE-2019-18988 carries a CVSS 3.1 score of 7.0 (HIGH), reflecting a serious security concern. The vulnerability requires local access to exploit with high attack complexity, meaning the attacker must first gain a foothold on the system or access the registry/configuration files through other means such as a file share. Low-level privileges are required, but no user interaction is needed. Successful exploitation results in high impact to confidentiality, integrity, and availability, as the decrypted credentials can grant full remote access to the system. The EPSS score of 8.8% (92.4th percentile) indicates a notable probability of exploitation. While not currently linked to ransomware campaigns, the ability to decrypt remote access credentials poses a significant threat, especially in environments where TeamViewer is used for unattended support across many endpoints.

Exploit Maturity

Public exploit code and detailed analysis are available for CVE-2019-18988 via WhyNotSecurity’s blog, which documents the shared AES key and provides tools for decrypting TeamViewer credentials. CISA has confirmed active exploitation by adding the vulnerability to the Known Exploited Vulnerabilities catalog with a remediation deadline of 2022-05-03. The EPSS score of 8.8% (92.4th percentile) indicates a notable probability of exploitation activity. The detailed public disclosure of the encryption key and decryption methodology makes it straightforward for attackers to exploit this vulnerability on any system where they can access the TeamViewer registry keys or configuration files.

Remediation

  1. Apply updates per vendor instructions as mandated by CISA KEV. Upgrade TeamViewer Desktop to a version beyond 14.7.1965 that addresses the shared encryption key vulnerability.
  2. After updating, rotate all TeamViewer access passwords including Unattended Access passwords, as previous credentials may have been decrypted by attackers using the known shared AES key.
  3. Restrict access to the Windows registry keys and configuration files where TeamViewer stores encrypted credentials (e.g., HKLM\SOFTWARE\TeamViewer), ensuring only authorized administrators and the TeamViewer service account can read these values.
  4. Audit systems for unauthorized remote access sessions by reviewing TeamViewer connection logs and correlating with expected usage patterns to identify potential compromise.
  5. Consider implementing additional layers of authentication for remote access, such as requiring two-factor authentication for all TeamViewer connections and disabling Unattended Access on endpoints where it is not strictly necessary.

Technical Details

CVE-2019-18988 stems from a fundamental cryptographic design weakness in TeamViewer Desktop. Since at least version 7.0.43148, the application has used the same hardcoded AES key for encrypting sensitive values such as OptionsPasswordAES stored in the Windows registry under HKLM\SOFTWARE\TeamViewer. The CVSS vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H indicates that while the attack requires local access and high complexity, the resulting impact on confidentiality, integrity, and availability is severe. In versions prior to 9.x, the Unattended Access password was encrypted using this same shared key, allowing any attacker with knowledge of the key and access to the registry to decrypt the password and establish remote sessions. While newer versions appear to have changed how the Unattended Access password is stored, the OptionsPasswordAES value still uses the same key, and if registry data is accessible through file shares or post-compromise scenarios, the credential exposure remains a viable attack path.

Frequently Asked Questions

Is CVE-2019-18988 being actively exploited?

Yes. CVE-2019-18988 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. Detailed exploit information including the shared AES key is publicly documented, and the EPSS score of 8.8% (92.4th percentile) indicates a notable probability of exploitation.

What products are affected by CVE-2019-18988?

CVE-2019-18988 affects TeamViewer Desktop through version 14.7.1965. The shared AES key issue has been present since at least version 7.0.43148, meaning a wide range of TeamViewer installations are potentially impacted.

How do I fix CVE-2019-18988?

Upgrade TeamViewer Desktop beyond version 14.7.1965. After updating, rotate all TeamViewer access passwords as previous credentials may have been compromised. Restrict access to registry keys where TeamViewer stores encrypted data and enable two-factor authentication for remote connections.

How severe is CVE-2019-18988?

CVE-2019-18988 has a CVSS 3.1 score of 7.0 (HIGH) and an EPSS score of 8.8% (92.4th percentile). While exploitation requires local access, the ability to decrypt remote access credentials using a publicly known key makes this a serious threat for environments with widespread TeamViewer deployment.

CVSS Score

7.0
HIGH(7.0)

EPSS Score

EPSS Score4.71%
EPSS Percentile91.1%

Dates

PublishedFebruary 7, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.