Tech News

TeamViewer Fixes 5 Security Flaws, Including a Remote Exploit

If you use TeamViewer as a remote support tool to help troubleshoot your users' issues, I encourage you to read what follows: a new version fixes 5 vulnerabilities in the TeamViewer clients for Windows, Linux, and macOS. One of them can be exploited remotely. Here's what you need to know.

TeamViewer has recently published a security bulletin regarding its TeamViewer Full Client and TeamViewer Host tools across all three operating systems (Windows, Linux, macOS)."TeamViewer strongly recommends that all users update to the latest available version as soon as possible", the company said.

There is no need to panic just yet: TeamViewer says it is not aware of any active exploitation of these flaws. However, TeamViewer is not like other software: it is a remote control tool. It is therefore very often installed on workstations, and sometimes even on servers (not ideal), and it includes an unattended access feature. In other words, it has everything attackers look for. In 2024, I also published an article about cybercriminals using TeamViewer access to deploy ransomware.

5 vulnerabilities, including one that can be exploited remotely

Let's now look at the vulnerabilities themselves and their impact on TeamViewer:

  • CVE-2026-92370 : the most serious one (CVSS 8.8 out of 10). This access control flaw allows a remote attacker to bypass, during session establishment, the permissions configured by the user. By modifying the access control settings of restricted features, the attacker can perform actions explicitly denied by the victim, with remote code execution potentially resulting. The security bulletin notes that user interaction is required, so an attack based on social engineering is likely.
  • CVE-2026-19743 : a directory traversal issue in the local IPC service. A local user with low privileges can send forged IPC commands to the service and write arbitrary files with NT AUTHORITY\SYSTEM or root privileges.
  • CVE-2026-92368 : a heap overflow in the processing of session recordings (.tvs files), on Linux and macOS from version 15.70 onward (CVSS 7.8). The attacker must convince the user to open a booby-trapped recording through the "Play or convert recorded session…" feature in order to execute code with the user's privileges.
  • CVE-2026-92369 : a TOCTOU race condition in the Windows installer restore mechanism (CVSS 7.3). A local attacker can replace backup files stored in a writable temporary directory before they are restored by the installer running with elevated privileges.
  • CVE-2026-92371 : a flaw in the Cloud Session Recording feature, on Linux only (CVSS 7.0). By exploiting a race condition between path validation and file access, an authenticated local attacker can trigger privileged operations on unintended locations.

In short, three of these flaws can lead to local privilege escalation.

Which versions should you install?

All of these vulnerabilities are fixed in TeamViewer 15.82, for both Full Client and Host. The vendor has also released patches for its other branches:

  • Windows 7 and Windows 8 : version 15.64.8
  • Branch 14.7 : version 14.7.48855, on Windows, Linux and macOS
  • Branch 13.2 : version 13.2.36230 on Windows, 13.2.153995 on Linux and 13.2.153994 on macOS

Upgrading is the only action recommended by the vendor to protect yourself from these TeamViewer flaws.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.