TeamViewer Full Client and Host Vulnerabilities Could Allow Command Execution and Privilege Escalation

Views: 92 views

540/69 Thursday, October 1, 2026

TeamViewer has released security updates to address five High-severity vulnerabilities in TeamViewer Full Client and Host on Windows, Linux, and macOS. The most severe vulnerability is CVE-2026-92370, with a CVSS score of 8.8, caused by improper permission controls during remote sessions. The flaw could allow an attacker to bypass user-defined permission settings and perform actions that should otherwise be restricted, potentially leading to command execution on the target system. TeamViewer stated that no public exploit has been released and there is currently no evidence that these vulnerabilities have been exploited in real-world attacks.

The other vulnerabilities include CVE-2026-19743, which could allow a user with limited privileges to write files with SYSTEM or root permissions and potentially escalate privileges; CVE-2026-92368, a heap-based buffer overflow on Linux and macOS that could lead to command execution if a user opens a specially crafted .tvs session recording file; CVE-2026-92369, a race condition in the installer rollback process on Windows that could result in privilege escalation; and CVE-2026-92371, which affects the Cloud Session Recording feature on Linux and could allow files to be created or modified in unintended locations with elevated privileges.

The vulnerabilities have been fixed in TeamViewer version 15.82, as well as in supported Maintenance and Legacy releases. Users and administrators should check the versions of TeamViewer Full Client and Host currently in use and update to the latest available release as soon as possible. TeamViewer stated that versions earlier than 15.82 on Windows, Linux, and macOS may be affected by some of the vulnerabilities, while users of older product releases should upgrade to the appropriate fixed version for their respective product branch.

Source: https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/