1. Summary
TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions.
TeamViewer strongly recommends that all users update to the latest available version as soon as possible.
2. Vulnerability details
I. Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients
|
CVE-ID |
|
|
Description |
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation. |
|
CVSS3.1 Score |
Base Score 7.8 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
|
|
Affected versions |
TeamViewer Full Client and Host
|
II. Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution
|
CVE-ID |
|
|
Description |
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user |
|
CVSS3.1 Score |
Base Score 7.8 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
|
|
Affected versions |
TeamViewer Full Client and Host
|
III. Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation
|
CVE-ID |
|
|
Description |
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. |
|
CVSS3.1 Score |
Base Score 7.3 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
|
|
Affected versions |
TeamViewer Full Client and Host
|
IV. Remote Session Access Control Bypass Leading to Remote Code Execution
|
CVE-ID |
|
|
Description |
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system. |
|
CVSS3.1 Score |
Base Score 8.8 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
|
|
Affected versions |
TeamViewer Full Client and Host
|
V. Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording
|
CVE-ID |
|
|
Description |
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system. |
|
CVSS3.1 Score |
Base Score 7.0 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
|
|
Affected versions |
TeamViewer Full Client and Host
|
These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases listed below.
TeamViewer is not aware of any public disclosure or active exploitation in the wild.
3. Affected software and versions
|
Product
|
Versions
|
Info
|
|---|---|---|
|
TeamViewer Full Client (Windows) |
< 15.82 |
|
|
TeamViewer Full Client (Linux) |
< 15.82 |
|
|
TeamViewer Full Client (MacOS) |
< 15.82 |
|
|
TeamViewer Host (Windows) |
< 15.82 |
|
|
TeamViewer Host (Linux) |
< 15.82 |
|
|
TeamViewer Host (MacOS) |
< 15.82 |
|
Legacy versions
|
Versions
|
Info
|
|---|---|---|
|
Teamviewer Full Client v15.64 (Windows 7 & 8) |
< 15.64.8 |
|
|
TeamViewer Full Client v14.7 (Windows) |
< 14.7.48855 |
|
|
TeamViewer Full Client v13.2 (Windows) |
< 13.2.36230 |
|
|
TeamViewer Full Client v14.7 (Linux) |
< 14.7.48855 |
|
|
TeamViewer Full Client v13.2 (Linux) |
< 13.2.153995 |
|
|
TeamViewer Full Client v14.7 (MacOS) |
< 14.7.48855 |
|
|
TeamViewer Full Client v13.2 (MacOS) |
< 13.2.153994 |
|
|
Teamviewer Host v15.64 (Windows 7 & 8) |
< 15.64.8 |
|
|
TeamViewer Host v14.7 (Windows) |
< 14.7.48855 |
|
|
TeamViewer Host v13.2 (Windows) |
< 13.2.36230 |
|
|
TeamViewer Host v14.7 (Linux) |
< 14.7.48855 |
|
|
TeamViewer Host v13.2 (Linux) |
< 13.2.153995 |
|
|
TeamViewer Host v14.7 (MacOS) |
< 14.7.48855 |
|
|
TeamViewer Host v13.2 (MacOS) |
< 13.2.153994 |
4. Solutions and mitigations
- Update to the latest version (15.82 or the latest version available)
5. Acknowledgements
TeamViewer would like to thank the security researchers who responsibly reported these issues and worked with us throughout the coordinated vulnerability disclosure process.