AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-13699

HIGH · CVSS 8.8 EPSS 25.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-07-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Windows. Its EPSS score suggests a 25.9% probability of exploitation in the next 30 days.

CVE
CVE-2020-13699
Severity
HIGH
CVSS
8.8
EPSS
25.90%
Windows

Original NVD Description

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)