CVE-2026-92369 Details
Description
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the TeamViewer Full Client and Host applications for Windows, prior to version 15.82. This vulnerability arises in the installer rollback mechanism, where a local low-privileged attacker can manipulate rollback backup files stored in a user-writable temporary directory. By replacing these files before they are restored by an elevated installer, the attacker can escalate privileges to NT AUTHORITY/SYSTEM. Exploitation requires precise timing to take advantage of the race condition, along with a rollback during the installation or update process.
Users are advised to update to the latest version of TeamViewer Full Client or Host. Version 15.82 or the latest available version can be downloaded from the TeamViewer website. For those using legacy versions, TeamViewer Full Client v15.64 (Windows 7 & 8), v14.7 (Windows, Linux, MacOS) or v13.2 (Windows, Linux, MacOS) are available. TeamViewer Host v15.64 (Windows 7 & 8), v14.7 (Windows, Linux, MacOS) or v13.2 (Windows, Linux, MacOS) can also be downloaded.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamViewer Full Client | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) |
CPE
Remediation
| |
| TeamViewer Host | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion