Description
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab containing [img]//http:// substrings.
In plain language
AI Worth attentionTeamSpeak Client 3.0.14 and earlier can be crashed by a remote, already-authenticated user—so if your staff connect using an older TeamSpeak client, you should act, because it can cause service disruption.
CVE-2014-7221 is a buffer overflow–based denial of service in TeamSpeak Client; a remote authenticated user can trigger a client crash by connecting to a channel with a different client instance and sending crafted chat/server tab content containing specific image URL patterns (e.g., [img]//http://...).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2014-7221 and every CVE in our database. Create a free account — no credit card required.
Create Free Account