¡¾Îó²îͨ¸æ¡¿TeamViewer í§Òâ´úÂëÖ´ÐÐÎó²î(CVE-2021-34858)

Ðû²¼Ê±¼ä 2021-08-31

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-34858

ʱ      ¼ä

2021-08-24

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥

ÊÇ

ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

TeamViewerÊÇÒ»¸öʹÓÃÆÕ±éµÄÔ¶³Ì¿ØÖÆÈí¼þ£¬£¬£¬£¬£¬£¬£¬ £¬Ëü¿ÉÒÔÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ʵÏÖ×ÀÃæ¹²ÏíºÍÎļþ´«Êä¡£¡£ ¡£ ¡£¡£

2021Äê8ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬TeamViewerÐû²¼¸üÐÂͨ¸æ£¬£¬£¬£¬£¬£¬£¬ £¬ÐÞ¸´ÁËTeamViewerÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34858£©ºÍÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-34859£©£¬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë¡¢µ¼Ö¶þ½øÖÆÎļþ±ÀÀ£»£»£»£»£»£»£»òµ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£ ¡£ ¡£¡£

TeamViewerí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34858£©

ÓÉÓÚTeamViewerÔÚʹÓÃÏÖÓÐTVS¾ÙÐÐ×°ÖÃʱÈÝÒ×Êܵ½ÎļþÆÊÎöÎÊÌâµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë²¢µ¼Ö¶þ½øÖÆÎļþÍ߽⡣¡£ ¡£ ¡£¡£µ«Ô¶³ÌʹÓôËÎó²îÐèÒªÓû§½»»¥ÒÔ¼°µÚÈý·½Îó²î¡£¡£ ¡£ ¡£¡£

 

TeamViewerÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-34859£©

ÓÉÓÚ¹²ÏíÄÚ´æÖÎÀíÖб£´æÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂTeamViewerЧÀÍÖ´ÐÐÔ½½ç¶ÁÈ¡¡£¡£ ¡£ ¡£¡£

 

Ó°Ïì¹æÄ£

TeamViewe [Linux] < v15.21.4

TeamViewe [Windows] < v15.21.4

TeamViewe [macOS] < v15.21.2

[½öÏÞ Windows]£ºÄ¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ £¬TeamViewer ×°ÖÃÔÚÊܱ£»£»£»£»£»£»£»¤µÄ Program Files Ŀ¼ÖС£¡£ ¡£ ¡£¡£ÈôÊÇÓû§ÓÐÒâÑ¡Ôñ½«Æä×°ÖÃÔÚÆäËüλÖ㬣¬£¬£¬£¬£¬£¬ £¬Ôò¹¥»÷Õß½«Äܹ»ÊµÏÖȨÏÞÌáÉý¡£¡£ ¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ £¬½¨ÒéʵʱÉý¼¶¸üе½ÒÔÏÂ×îа汾£º

TeamViewe [Linux] v15.21.4

TeamViewe [Windows] v15.21.6

TeamViewe [macOS] v15.21.2

ÏÂÔØÁ´½Ó£º

https://www.teamviewer.cn/cn/

 

0x03 ²Î¿¼Á´½Ó

https://community.teamviewer.com/English/discussion/117791/linux-v15-21-4

https://community.teamviewer.com/English/categories/change-logs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34858

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-31

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png