TeamViewer - Bounty Program
The TeamViewer suite of remote connectivity, augmented reality, IT management, and customer-first engagement solutions empowers you to connect to any device to support anyone, any process, or anything — from anywhere, anytime.
Reward
Program
Hacktivity
Company
TeamViewer Germany GmbH is the market leader for remote control.
It has been installed over 2.3 billions time on any type of operating system and provides connectivity for anyone, anywhere, anytime.
Program Rules
- We strongly believe into crowd testing and responsible disclosure model. It helps the industry, it protects users and contributes making the internet a safer place.
- If you believe you've found a security vulnerability in our service, we are happy to work with you to resolve the issue promptly and ensure that you are fairly rewarded for your discovery
- Any type of denial of service attacks is strictly forbidden, as well as any interference with network equipment and TeamViewer Germany GmbH infrastructure. Your work should be non-destructive and remain within a proof of concept framework.
Eligibility and Responsible Disclosure
- We are happy to thank everyone who submits valid reports which help us improve the security of TeamViewer Germany GmbH however, only those that meet the following eligibility requirements may receive a monetary reward:
- You must be the first reporter of a vulnerability.
- The vulnerability must be a qualifying vulnerability (see below)
- Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through yeswehack.com
- You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
- You must avoid tests that could cause degradation or interruption of our service (refrain from using automated tools, and limit yourself about requests per second).
- You must not leak, manipulate, or destroy any user data.
- You must not be a former or current employee of TeamViewer Germany GmbH nor one of its contractor.
- Reports about vulnerabilities are examined and validated by our security analysts.
Scope details
For now, the scope of this program is limited to the following:
TeamViewer Remote
-
TeamViewer Remote Client
- TeamViewer Remote desktop client. Available for free download here: https://www.teamviewer.com/en/products/teamviewer/
-
web.teamviewer.com
- web.teamviewer.com is the web version of the client
-
account.teamviewer.com
- account.teamviewer.com is the associated login service
-
login.teamviewer.com
- login.teamviewer.com is the management console of TeamViewer Remote
-
TeamViewer Remote Control App
- TeamViewer Remote Control App is the mobile version of the TeamViewer client. Available for Android and iOS.
-
TeamViewer QuickSupport App
- TeamViewer QuickSupport App is a mobile client only for incoming remote sessions. Available for Android and iOS.
-
Teamviewer Host App
- Teamviewer Host App is a mobile app for unattended access to a mobile device. Only available for Android.
Backend services you might directly interact with from the client app are considered part of the scope.
License Restriction Bypass – Rewards
All vulnerability reports that demonstrate an issue relying on bypassing our license limitations will be considered as Informative and closed without reward, except if a concrete and severe business impact can be demonstrated. In such instances, it will be a case by case analysis.
The vulnerability leads to a relevant financial impact on the business, can include:
- Noticeable additional infrastructure or service costs
- Persistent and scalable access to high-value, license-restricted features (beyond minor usage extensions or simple account configuration changes)
On the contrary, low impact vulnerabilities include:
- Bypasses limited to minor or isolated increases in usage, such as:
- Adding a small number of additional users/devices within a single account
- Accessing higher-tier features in a non-scalable way
- Cases where the impact is considered negligible from a financial or security perspective
Reward
| Asset value | CVSS | CVSS | CVSS | CVSS |
|---|---|---|---|---|
| €200 | €1,000 | €4,000 | €10,000 | |
| €100 | €500 | €2,000 | €5,000 |
Systemic issues
We appreciate all valid reports submitted to our program that enhance our security. However, please note that if a similar issue (see definition in 'More info') has already been reported, by you or any other hunter, the reward will be decreasing according to these percentages.
Scopes
| Scope | Type | Asset value | Expand rewards grid |
|---|---|---|---|
https://www.teamviewer.com/en/products/teamviewer/ | Application | ||
Low Medium High Critical | |||
https://web.teamviewer.com | Web application | ||
Low Medium High Critical | |||
https://account.teamviewer.com | Web application | ||
Low Medium High Critical | |||
https://login.teamviewer.com | Web application | ||
Low Medium High Critical | |||
https://play.google.com/store/apps/details?id=com.teamviewer.teamviewer.market.mobile&hl=en&gl=US | Mobile application Android | ||
Low Medium High Critical | |||
https://play.google.com/store/apps/details?id=com.teamviewer.quicksupport.market&hl=en&gl=US | Mobile application Android | ||
Low Medium High Critical | |||
https://play.google.com/store/apps/details?id=com.teamviewer.host.market&hl=en&gl=US | Mobile application Android | ||
Low Medium High Critical | |||
https://apps.apple.com/de/app/teamviewer-remote-control/id692035811 | Mobile application IOS | ||
Low Medium High Critical | |||
https://apps.apple.com/de/app/teamviewer-quicksupport/id661649585 | Mobile application IOS | ||
Low Medium High Critical | |||
Out of scopes
- All domains not listed In-Scope
Vulnerability types
Qualifying vulnerabilities
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Remote Code Execution (RCE)
- Insecure Direct Object Reference (IDOR)
- Horizontal and vertical privilege escalation
- Authentication bypass & broken authentication
- Business Logic Errors vulnerability with real security impact
- Local files access and manipulation (LFI, RFI, XXE, SSRF, XSPA)
- Cross-Origin Resource Sharing (CORS) with real security impact
- Cross-site Request Forgery (CSRF) with real security impact
- Open Redirect
- Exposed secrets, credentials or sensitive information on an asset under our control and affecting at least one of our scopes
Non-qualifying vulnerabilities
- Broken Link/Social media Hijacking
- Tabnabbing
- Leaked User IDs
- Missing cookie flags
- Content/Text injections
- Clickjacking/UI redressing
- Denial of Service (DoS) attacks
- Recently disclosed CVEs (less than 30 days sinces patch release)
- CVEs without exploitable vulnerabilities and PoC
- Open ports or services without exploitable vulnerabilities and PoC
- Social engineering of staff or contractors
- Presence of autocomplete attribute on web forms
- Vulnerabilities affecting outdated browsers or platforms
- Self-XSS or XSS that cannot be used to impact other users
- Any hypothetical flaw or best practices without exploitable vulnerabilities and PoC
- SSL/TLS issues (e.g. expired certificates, best practices)
- Unexploitable vulnerabilities (e.g. Self-XSS, XSS or Open Redirect through HTTP headers...)
- Reports with attack scenarios requiring MITM or physical access to victim's device
- Missing security-related HTTP headers which do not lead directly to an exploitable vulnerability and PoC
- Low severity Cross-Site Request Forgery (CSRF) (e.g. Unauthenticated / Logout / Login / Products cart updates...)
- Invalid or missing email security records (e.g. SPF, DKIM, DMARC)
- Session management issues (e.g. lack of expiration, no logout on password change, concurrent sessions)
- Disclosure of information without exploitable vulnerabilities and PoC (e.g. stack traces, path disclosure, directory listings, software versions, IP disclosure, 3rd party secrets, EXIF Metadata, Origin IP)
- CSV injection
- Malicious file upload (e.g. EICAR files, .EXE)
- HTTP Strict Transport Security Header (HSTS)
- Subdomain takeover without a full exploitable vulnerability and PoC or not applicable to the scope
- Blind SSRF without exploitable vulnerabilities and PoC (e.g. DNS & HTTP pingback, Wordpress XMLRPC)
- Lack or bypass of rate-limiting, brute-forcing or captcha issues
- User enumeration (e.g. email, alias, GUID, phone number, common CMS endpoints)
- Weak password policies (e.g. length, complexity, reuse)
- Ability to spam users (email / SMS / direct messages flooding)
- Disclosed or misconfigured public API keys (e.g. Google Maps, Firebase, analytics tools...)
- Password reset token sent via HTTP referer to external services (e.g. analytics / ads platforms)
- Stolen secrets, credentials or information gathered from a third-party asset that we have no control over
- Exposed secrets, credentials or information on an asset under our control that are not applicable to the program’s scope
- Pre-account takeover (e.g. account creation via oAuth)
- GraphQL Introspection is enabled
Reports of leaks and exposed credentials
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and policy. To summarize our policy, you may refer to the below table:
Hunting requirements
Account access
Download and use the binary from https://www.teamviewer.com/en/products/teamviewer
For the Web Version go to: https://web.teamviewer.com
Login Service: https://account.teamviewer.com
Management Console (MCO): https://login.teamviewer.com
Android Apps: https://play.google.com/store/apps/developer?id=TeamViewer&hl=en&gl=US&pli=1
TeamViewer Remote Control
TeamViewer QuickSupport
TeamViewer Host
iOS Apps:
TeamViewer Quick Support: https://apps.apple.com/us/app/teamviewer-quicksupport/id661649585
TeamViewer Remote Control: https://apps.apple.com/us/app/teamviewer/id692035811
Hunters collaboration
When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.
For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.