{"id":10738,"date":"2017-12-06T12:11:16","date_gmt":"2017-12-06T20:11:16","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/12\/06\/news-4510\/"},"modified":"2017-12-06T12:11:16","modified_gmt":"2017-12-06T20:11:16","slug":"news-4510","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/12\/06\/news-4510\/","title":{"rendered":"Use TeamViewer? Fix this dangerous permissions bug with an update"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 06 Dec 2017 19:42:54 +0000<\/strong><\/p>\n<p>TeamViewer, the remote control\/web conference program used to share files and desktops,\u00a0 is suffering from a case of &#8220;patch it now.&#8221; Issued yesterday, the fix addresses an issue where one user can <a href=\"https:\/\/www.techworm.net\/2017\/12\/teamviewer-vulnerability-allows-users-sharing-desktop-session-gain-control-others-pc.html\" target=\"_blank\" rel=\"noopener\">gain control of another&#8217;s PC without permission<\/a>.<\/p>\n<p>Windows, Mac, and LinuxOS are all apparently affected by this bug, which was <a href=\"https:\/\/www.reddit.com\/r\/netsec\/comments\/7hfd84\/be_careful_on_teamviewer_switch_sides_bugtake\/\" target=\"_blank\" rel=\"noopener\">first revealed over on Reddit<\/a>. According to TeamViewer, the Windows patch is already out, with Mac and Linux to follow on soon. It&#8217;s definitely worth updating, as there are shenanigans to be had whether acting as client or server:<\/p>\n<blockquote>\n<h3>As the Server: Enables extra menu item options on the right side pop-up menu. Most useful so far to enable the &#8220;switch sides&#8221; feature, which is normally only active after you have already authenticated control with the client, and initiated a change of control\/sides.<\/h3>\n<h3>As the Client: Allows for control of mouse with disregard to server&#8217;s current control settings and permissions.<\/h3>\n<\/blockquote>\n<p>This is all done via an injectible C++ DLL. The file, injected into TeamViewer.exe, then allows the presenter\u00a0<em>or<\/em> the viewer to take full control.<\/p>\n<p>It&#8217;s worth noting that even if you have automatic updates set, it might take between three to seven days for the patch to be applied.<\/p>\n<p>Many <a href=\"https:\/\/www.wired.co.uk\/article\/malwarebytes\" target=\"_blank\" rel=\"noopener\">tech support scammers<\/a> make use of programs such as TeamViewer, but with this new technique they wouldn&#8217;t have to first trick the victim into handing over control. While in theory a victim should know immediately if a scammer has gained unauthorised control over their system and kill off the session straight away, in practice it doesn&#8217;t always pan out like that.<\/p>\n<p>TeamViewer has had other problems in the past, including being used as a way to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/surprise-ransomware-installed-via-teamviewer-and-executes-from-memory\/\" target=\"_blank\" rel=\"noopener\">distribute ransomware<\/a>, denying being hacked after <a href=\"https:\/\/www.theregister.co.uk\/2016\/06\/01\/teamviewer_mass_breach_report\/\" target=\"_blank\" rel=\"noopener\">bank accounts were drained<\/a>, and even being <a href=\"https:\/\/www.theregister.co.uk\/2017\/03\/09\/talktalk_blocks_teamviewer\/\" target=\"_blank\" rel=\"noopener\">temporarily blocked<\/a> by a UK ISP. Controversies aside, you should perhaps consider uninstalling the program until the relevant patch for your operating system is ready to install. This could prove to be a major headache for the unwary until the problem is fully solved.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/use-teamviewer-fix-this-dangerous-permissions-bug-with-an-update\/\">Use TeamViewer? Fix this dangerous permissions bug with an update<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/use-teamviewer-fix-this-dangerous-permissions-bug-with-an-update\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 06 Dec 2017 19:42:54 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/use-teamviewer-fix-this-dangerous-permissions-bug-with-an-update\/' title='Use TeamViewer? Fix this dangerous permissions bug with an update'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2015\/03\/photodune-8894073-cyber-spy-mode-on-s.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A potentially dangerous permissions bug in TeamViewer grants unauthorised access to either the client or the server\u2014and patches may take up to a week to fully roll out. <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/exploits\/\" rel=\"category tag\">Exploits<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/bug\/\" rel=\"tag\">bug<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/client\/\" rel=\"tag\">client<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/exploit\/\" rel=\"tag\">exploit<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/server\/\" rel=\"tag\">server<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/teamviewer\/\" rel=\"tag\">teamviewer<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/use-teamviewer-fix-this-dangerous-permissions-bug-with-an-update\/' title='Use TeamViewer? Fix this dangerous permissions bug with an update'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/use-teamviewer-fix-this-dangerous-permissions-bug-with-an-update\/\">Use TeamViewer? Fix this dangerous permissions bug with an update<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11210,16865,4503,11638,10987,12046,16866],"class_list":["post-10738","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bug","tag-client","tag-cybercrime","tag-exploit","tag-exploits","tag-server","tag-teamviewer"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10738"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10738\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}