avatar
Bug bounty
Public

TeamViewer - Bounty Program

The TeamViewer suite of remote connectivity, augmented reality, IT management, and customer-first engagement solutions empowers you to connect to any device to support anyone, any process, or anything — from anywhere, anytime.

Reward

Bounty
Hall of fame
€100
Low
€200
Medium
€1,000
High
€4,000
Critical
€10,000

Program

Avg reward
-
Max reward
-

Scopes
9
Supported languages
English

Hacktivity

Reports
906
1st response
< 1 day
Reports last 24h
1
Reports last week
18
Reports this month
37

Company

TeamViewer Germany GmbH is the market leader for remote control.

It has been installed over 2.3 billions time on any type of operating system and provides connectivity for anyone, anywhere, anytime.

Program Rules

  • We strongly believe into crowd testing and responsible disclosure model. It helps the industry, it protects users and contributes making the internet a safer place.
  • If you believe you've found a security vulnerability in our service, we are happy to work with you to resolve the issue promptly and ensure that you are fairly rewarded for your discovery
  • Any type of denial of service attacks is strictly forbidden, as well as any interference with network equipment and TeamViewer Germany GmbH infrastructure. Your work should be non-destructive and remain within a proof of concept framework.

Eligibility and Responsible Disclosure

  • We are happy to thank everyone who submits valid reports which help us improve the security of TeamViewer Germany GmbH however, only those that meet the following eligibility requirements may receive a monetary reward:
  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability (see below)
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through yeswehack.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
  • You must avoid tests that could cause degradation or interruption of our service (refrain from using automated tools, and limit yourself about requests per second).
  • You must not leak, manipulate, or destroy any user data.
  • You must not be a former or current employee of TeamViewer Germany GmbH nor one of its contractor.
  • Reports about vulnerabilities are examined and validated by our security analysts.

Scope details

For now, the scope of this program is limited to the following:

TeamViewer Remote

  • TeamViewer Remote Client

  • web.teamviewer.com

    • web.teamviewer.com is the web version of the client
  • account.teamviewer.com

    • account.teamviewer.com is the associated login service
  • login.teamviewer.com

    • login.teamviewer.com is the management console of TeamViewer Remote
  • TeamViewer Remote Control App

    • TeamViewer Remote Control App is the mobile version of the TeamViewer client. Available for Android and iOS.
  • TeamViewer QuickSupport App

    • TeamViewer QuickSupport App is a mobile client only for incoming remote sessions. Available for Android and iOS.
  • Teamviewer Host App

    • Teamviewer Host App is a mobile app for unattended access to a mobile device. Only available for Android.

Backend services you might directly interact with from the client app are considered part of the scope.

License Restriction Bypass – Rewards

All vulnerability reports that demonstrate an issue relying on bypassing our license limitations will be considered as Informative and closed without reward, except if a concrete and severe business impact can be demonstrated. In such instances, it will be a case by case analysis.

The vulnerability leads to a relevant financial impact on the business, can include:

  • Noticeable additional infrastructure or service costs
  • Persistent and scalable access to high-value, license-restricted features (beyond minor usage extensions or simple account configuration changes)

On the contrary, low impact vulnerabilities include:

  • Bypasses limited to minor or isolated increases in usage, such as:
  • Adding a small number of additional users/devices within a single account
  • Accessing higher-tier features in a non-scalable way
  • Cases where the impact is considered negligible from a financial or security perspective

Reward

Asset value CVSS
Low
CVSS
Medium
CVSS
High
CVSS
Critical
Critical
€200€1,000€4,000€10,000
High
€100€500€2,000€5,000

Systemic issues

1st report100%
2nd report100%
3rd report75%
4th report50%
5th report25%
6th+ report0%

We appreciate all valid reports submitted to our program that enhance our security. However, please note that if a similar issue (see definition in 'More info') has already been reported, by you or any other hunter, the reward will be decreasing according to these percentages.


Scopes

ScopeTypeAsset value
https://www.teamviewer.com/en/products/teamviewer/
Application
Critical
Low
€200
Medium
€1,000
High
€4,000
Critical
€10,000
https://web.teamviewer.com
Web application
Critical
Low
€200
Medium
€1,000
High
€4,000
Critical
€10,000
https://account.teamviewer.com
Web application
Critical
Low
€200
Medium
€1,000
High
€4,000
Critical
€10,000
https://login.teamviewer.com
Web application
Critical
Low
€200
Medium
€1,000
High
€4,000
Critical
€10,000
https://play.google.com/store/apps/details?id=com.teamviewer.teamviewer.market.mobile&hl=en&gl=US
Mobile application Android
High
Low
€100
Medium
€500
High
€2,000
Critical
€5,000
https://play.google.com/store/apps/details?id=com.teamviewer.quicksupport.market&hl=en&gl=US
Mobile application Android
High
Low
€100
Medium
€500
High
€2,000
Critical
€5,000
https://play.google.com/store/apps/details?id=com.teamviewer.host.market&hl=en&gl=US
Mobile application Android
High
Low
€100
Medium
€500
High
€2,000
Critical
€5,000
https://apps.apple.com/de/app/teamviewer-remote-control/id692035811
Mobile application IOS
High
Low
€100
Medium
€500
High
€2,000
Critical
€5,000
https://apps.apple.com/de/app/teamviewer-quicksupport/id661649585
Mobile application IOS
High
Low
€100
Medium
€500
High
€2,000
Critical
€5,000

Out of scopes

  • All domains not listed In-Scope

Vulnerability types

Qualifying vulnerabilities

  • SQL Injection (SQLi)
  • Cross-Site Scripting (XSS)
  • Remote Code Execution (RCE)
  • Insecure Direct Object Reference (IDOR)
  • Horizontal and vertical privilege escalation
  • Authentication bypass & broken authentication
  • Business Logic Errors vulnerability with real security impact
  • Local files access and manipulation (LFI, RFI, XXE, SSRF, XSPA)
  • Cross-Origin Resource Sharing (CORS) with real security impact
  • Cross-site Request Forgery (CSRF) with real security impact
  • Open Redirect
  • Exposed secrets, credentials or sensitive information on an asset under our control and affecting at least one of our scopes

Non-qualifying vulnerabilities

  • Broken Link/Social media Hijacking
  • Tabnabbing
  • Leaked User IDs
  • Missing cookie flags
  • Content/Text injections
  • Clickjacking/UI redressing
  • Denial of Service (DoS) attacks
  • Recently disclosed CVEs (less than 30 days sinces patch release)
  • CVEs without exploitable vulnerabilities and PoC
  • Open ports or services without exploitable vulnerabilities and PoC
  • Social engineering of staff or contractors
  • Presence of autocomplete attribute on web forms
  • Vulnerabilities affecting outdated browsers or platforms
  • Self-XSS or XSS that cannot be used to impact other users
  • Any hypothetical flaw or best practices without exploitable vulnerabilities and PoC
  • SSL/TLS issues (e.g. expired certificates, best practices)
  • Unexploitable vulnerabilities (e.g. Self-XSS, XSS or Open Redirect through HTTP headers...)
  • Reports with attack scenarios requiring MITM or physical access to victim's device
  • Missing security-related HTTP headers which do not lead directly to an exploitable vulnerability and PoC
  • Low severity Cross-Site Request Forgery (CSRF) (e.g. Unauthenticated / Logout / Login / Products cart updates...)
  • Invalid or missing email security records (e.g. SPF, DKIM, DMARC)
  • Session management issues (e.g. lack of expiration, no logout on password change, concurrent sessions)
  • Disclosure of information without exploitable vulnerabilities and PoC (e.g. stack traces, path disclosure, directory listings, software versions, IP disclosure, 3rd party secrets, EXIF Metadata, Origin IP)
  • CSV injection
  • Malicious file upload (e.g. EICAR files, .EXE)
  • HTTP Strict Transport Security Header (HSTS)
  • Subdomain takeover without a full exploitable vulnerability and PoC or not applicable to the scope
  • Blind SSRF without exploitable vulnerabilities and PoC (e.g. DNS & HTTP pingback, Wordpress XMLRPC)
  • Lack or bypass of rate-limiting, brute-forcing or captcha issues
  • User enumeration (e.g. email, alias, GUID, phone number, common CMS endpoints)
  • Weak password policies (e.g. length, complexity, reuse)
  • Ability to spam users (email / SMS / direct messages flooding)
  • Disclosed or misconfigured public API keys (e.g. Google Maps, Firebase, analytics tools...)
  • Password reset token sent via HTTP referer to external services (e.g. analytics / ads platforms)
  • Stolen secrets, credentials or information gathered from a third-party asset that we have no control over
  • Exposed secrets, credentials or information on an asset under our control that are not applicable to the program’s scope
  • Pre-account takeover (e.g. account creation via oAuth)
  • GraphQL Introspection is enabled

Reports of leaks and exposed credentials

In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and policy. To summarize our policy, you may refer to the below table:

Type of leak
Source of leak is in-scope
Source of leak belongs to the Organization and is out-of-scope
Source of leak does not belong to the Organization and is out-of-scope
Impact is in-scope (e.g. valid credentials on an in-scope asset)
checked Eligible
checked Eligible
checked Not eligible
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset)
checked Eligible
checked Not eligible
checked Not eligible

Hunting requirements

Account access

Download and use the binary from https://www.teamviewer.com/en/products/teamviewer

For the Web Version go to: https://web.teamviewer.com
Login Service: https://account.teamviewer.com
Management Console (MCO): https://login.teamviewer.com

Android Apps: https://play.google.com/store/apps/developer?id=TeamViewer&hl=en&gl=US&pli=1
TeamViewer Remote Control
TeamViewer QuickSupport
TeamViewer Host

iOS Apps:
TeamViewer Quick Support: https://apps.apple.com/us/app/teamviewer-quicksupport/id661649585
TeamViewer Remote Control: https://apps.apple.com/us/app/teamviewer/id692035811


Hunters collaboration

When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.

For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.

To submit a vulnerability report, you need to login with your hunter account.