CVE-2026-92369
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Summary
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TeamViewer | Full Client | 15.0 < 15.82 | affected |
| TeamViewer | Full Client | 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) | affected |
| TeamViewer | Full Client | 14.7.0 < 14.7.48855 | affected |
| TeamViewer | Full Client | 13.2.0 < 13.2.36230 | affected |
| TeamViewer | Host | 15.0 < 15.82 | affected |
| TeamViewer | Host | 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) | affected |
| TeamViewer | Host | 14.7.0 < 14.7.48855 | affected |
| TeamViewer | Host | 13.2.0 < 13.2.36230 | affected |
Weaknesses
- CWE-367: CWE-367 Time-of-check time-of-use (TOCTOU) race condition
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.