A critical vulnerability in TeamViewer Desktop (versions 7 through 14.7.1965) allows attackers to bypass remote-login access controls due to the use of a static AES-128-CBC key and IV for encrypting sensitive information (such as Unattended Access and Options passwords) in the Windows registry and configuration files. The static key and IV are not version-specific, making the attack applicable across multiple versions. If an attacker obtains the relevant registry or configuration keys, either locally or from an exposed file share or online source, they can decrypt the stored passwords. This enables unauthorized remote access and potential privilege escalation to NT AUTHORITY\SYSTEM, especially when combined with TeamViewer's scripting engine and service context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit post-exploitation module written in Ruby, designed to extract and decrypt stored TeamViewer passwords from Windows systems. The module targets multiple versions of TeamViewer (7 through 15) by querying specific registry keys for encrypted password values, which it then attempts to decrypt using a hardcoded AES key and IV. Additionally, the module can interact with the TeamViewer application window to extract credentials directly from the UI using Windows API calls via Meterpreter's Railgun extension. Extracted credentials are displayed to the attacker and stored as loot within Metasploit. The module references CVE-2019-18988 and is intended for use on compromised Windows systems where a Meterpreter session is available. The code is operational and provides real credential extraction functionality, not just proof-of-concept or detection.
This repository contains a proof-of-concept exploit for CVE-2019-18988, targeting TeamViewer version 7 on Windows. The main file, CVE-2019-18988.py, is a Python script that demonstrates how to decrypt the TeamViewer password stored in the Windows registry at 'HKLM\SOFTWARE\WOW6432Node\TeamViewer\Version7'. The script uses a hardcoded AES key and IV to decrypt a provided password value (in hex format), then prints the plaintext password. The exploit requires local access to the system to retrieve the encrypted password from the registry. The repository also includes a minimal README.md. The exploit demonstrates the vulnerability but does not automate extraction from the registry; it expects the user to supply the encrypted value.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.