First published: Fri Jun 28 2019(Updated: )
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teamwire | >=1.5.1<1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-17170 is classified as critical due to its potential for remote code execution.
To address CVE-2018-17170, update the Teamwire Desktop Client to version 1.9.0 or later.
CVE-2018-17170 affects the Teamwire Desktop Client versions 1.5.1 through 1.8.x on Windows.
CVE-2018-17170 is a code injection vulnerability that can lead to remote code execution.
CVE-2018-17170 was disclosed in November 2018, highlighting the need for immediate updates to impacted software.