Critical TeamViewer Flaws Allow Remote Code Execution
Key Takeaways TeamViewer has issued critical security updates to address five high-severity vulnerabilities across its Full Client, Host, and related components. The flaws affect Windows, Linux, and...
Key Takeaways
- TeamViewer has issued critical security updates to address five high-severity vulnerabilities across its Full Client, Host, and related components.
- The flaws affect Windows, Linux, and macOS installations, with one vulnerability potentially leading to remote code execution.
- The most severe vulnerability, CVE-2026-92370, carries a CVSS score of 8.8 and could allow attackers to bypass configured remote session permissions.
- Users are strongly advised to update TeamViewer clients to version 15.82 or the latest available patch immediately.
TeamViewer Patches Critical Flaws, Including Remote Code Execution Vulnerability
TeamViewer has released crucial security updates to mitigate five high-severity vulnerabilities impacting its Full Client, Host, and associated components across Windows, Linux, and macOS platforms. The most critical of these flaws could enable attackers to circumvent established remote-session permissions, potentially leading to arbitrary code execution on vulnerable systems.
Table Of Content
The company has urged its user base to update their TeamViewer clients to version 15.82 or the most recent available version. TeamViewer stated it has no current knowledge of these vulnerabilities being publicly disclosed or actively exploited in the wild.
Privilege Escalation and Path Traversal
A significant privilege escalation vulnerability, identified as CVE-2026-19743, affects TeamViewer Full Client and Host installations running versions prior to 15.82 on Windows, Linux, and macOS. This local Inter-Process Communication (IPC) flaw allows authenticated users with low privileges to manipulate file paths, enabling them to write arbitrary files with elevated SYSTEM or root privileges.
This vulnerability has been assigned a CVSS score of 7.8 and is categorized under CWE-22, which denotes an improper limitation of a pathname to a restricted directory, commonly known as path traversal. The issue also extends to several supported legacy and maintenance releases, including TeamViewer versions 15.64, 14.7, and 13.2 on specific operating systems.
Additional High-Severity Vulnerabilities
TeamViewer also addressed CVE-2026-92369, a time-of-check time-of-use (TOCTOU) race condition found within the Windows installer’s rollback mechanism. This flaw could allow a local attacker with low privileges to replace backup files in a user-writable temporary directory before an elevated installer restores them. If timed successfully during an installation, update, or rollback, this attack could lead to SYSTEM-level privileges.
Another vulnerability, CVE-2026-92371, impacts the Cloud Session Recording function on Linux due to improper link resolution during file access. A local, authenticated attacker could exploit a race condition to redirect privileged file operations to unintended locations. This issue affects Linux TeamViewer Full Client and Host versions from 15.0 up to, but not including, 15.82.
CVE-2026-92368 describes a heap-based buffer overflow that occurs when processing TeamViewer .tvs session recording files on Linux and macOS. The vulnerability arises from a size mismatch during the decompression of recorded session data. An attacker could craft a malicious session recording file and trick a victim into opening it via the “Play or convert recorded session” feature. Successful exploitation could lead to arbitrary code execution with the permissions of the logged-in user. This vulnerability affects TeamViewer versions from 15.70 up to, but not including, 15.82 on Linux and macOS.
The most critical flaw, CVE-2026-92370, boasts the highest CVSS score of 8.8. This vulnerability could allow authenticated remote attackers to bypass user-configured restrictions and execute denied actions by manipulating access-control parameters. TeamViewer warned that this flaw could result in unauthorized activities and potentially remote code execution on the affected endpoint.
What You Should Do
- Immediately update all TeamViewer Full Client or Host installations to version 15.82 or the latest supported maintenance release.
- Review and enforce strict TeamViewer access-control settings, limiting remote-access privileges to the absolute minimum necessary.
- Restrict local administrative access to managed endpoints to prevent low-privileged users from exploiting local vulnerabilities.
- Monitor for any unusual installer activity, suspicious session-recording files, or unexpected modifications to protected system files.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.