MEDIUM · 6.6

CVE-2023-0837

An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings...

Vulnerability Description

An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TeamviewerRemote>= 15.41, < 15.42.8
AppleMacos-
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-0837?

CVE-2023-0837 is a vulnerability with a CVSS score of 6.6 (MEDIUM). An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings...

How severe is CVE-2023-0837?

CVE-2023-0837 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-0837?

Check the references section above for vendor advisories and patch information. Affected products include: Teamviewer Remote, Apple Macos, Microsoft Windows.