CVE-2026-19743

Summary

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

Affected Software

VendorProductVersion RangeStatus
TeamViewerFull Client15.0 < 15.82affected
TeamViewerFull Client15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)affected
TeamViewerFull Client14.7.0 (Windows) < 14.7.48855 (Windows)affected
TeamViewerFull Client13.2.0 (Windows) < 13.2.36230 (Windows)affected
TeamViewerFull Client14.7.0 (Linux) < 14.7.48855 (Linux)affected
TeamViewerFull Client13.2.0 (Linux) < 13.2.153995 (Linux)affected
TeamViewerFull Client14.7.0 (MacOS) < 14.7.48855 (MacOS)affected
TeamViewerFull Client13.2.0 (MacOS) < 13.2.153994 (MacOS)affected
TeamViewerHost15.0 < 15.82affected
TeamViewerHost15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)affected
TeamViewerHost14.7.0 (Windows) < 14.7.48855 (Windows)affected
TeamViewerHost13.2.0 (Windows) < 13.2.36230 (Windows)affected
TeamViewerHost14.7.0 (Linux) < 14.7.48855 (Linux)affected
TeamViewerHost13.2.0 (Linux) < 13.2.153995 (Linux)affected
TeamViewerHost14.7.0 (MacOS) < 14.7.48855 (MacOS)affected
TeamViewerHost13.2.0 (MacOS) < 13.2.153994 (MacOS)affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

References