TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions.
TeamViewer strongly recommends that all users update to the latest available version as soon as possible.
2. Vulnerability details
I. Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
Base Score 7.8 (High)
CVSS3.1 Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
TeamViewer Full Client and Host
Prior V15.82 (Windows, MacOS, Linux)
Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows, Linux), V13.2 (Windows, Linux)
II. Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user
Base Score 7.8 (High)
CVSS3.1 Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-122: Heap-based Buffer Overflow
TeamViewer Full Client and Host
From V15.70 prior V15.82 (Linux, MacOS)
From V15.70 prior V15.82 (Linux, MacOS)
III. Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Base Score 7.3 (High)
CVSS3.1 Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
TeamViewer Full Client and Host
Prior V15.82 (Windows)
Prior V15.82 (Windows)
Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows), V13.2 (Windows)
Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows), V13.2 (Windows)
IV. Remote Session Access Control Bypass Leading to Remote Code Execution
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Base Score 8.8 (High)
CVSS3.1 Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-284: Improper Access Control
TeamViewer Full Client and Host
Prior V15.82 (Windows, Linux, MacOS)
Prior V15.82 (Windows, Linux, MacOS)
Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows, Linux, MacOS), V13.2 (Windows, Linux, MacOS)
Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows, Linux, MacOS), V13.2 (Windows, Linux, MacOS)
V. Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Base Score 7.0 (High)
CVSS3.1 Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-59: Improper Link Resolution Before File Access ('Link Following')
TeamViewer Full Client and Host
From V15.0 prior V15.82 (Linux)
From V15.0 prior V15.82 (Linux)
These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases listed below.
TeamViewer is not aware of any public disclosure or active exploitation in the wild.
3. Affected software and versions
TeamViewer Full Client (Windows)
TeamViewer Full Client (Linux)
TeamViewer Full Client (MacOS)
TeamViewer Host (Windows)
TeamViewer Host (Linux)
TeamViewer Host (MacOS)
Teamviewer Full Client v15.64 (Windows 7 & 8)
TeamViewer Full Client v14.7 (Windows)
TeamViewer Full Client v13.2 (Windows)
TeamViewer Full Client v14.7 (Linux)
TeamViewer Full Client v13.2 (Linux)
TeamViewer Full Client v14.7 (MacOS)
TeamViewer Full Client v13.2 (MacOS)
Teamviewer Host v15.64 (Windows 7 & 8)
TeamViewer Host v14.7 (Windows)
TeamViewer Host v13.2 (Windows)
TeamViewer Host v14.7 (Linux)
TeamViewer Host v13.2 (Linux)
TeamViewer Host v14.7 (MacOS)
TeamViewer Host v13.2 (MacOS)
4. Solutions and mitigations
Update to the latest version (15.82 or the latest version available)
TeamViewer would like to thank the security researchers who responsibly reported these issues and worked with us throughout the coordinated vulnerability disclosure process.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
