PT-2025-26744 · Teamviewer · Teamviewer

·

CVE-2025-36537

·

Published

2025-06-24

·

Updated

2026-03-01

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TeamViewer versions prior to 15.67
Description: The issue is related to an incorrect permission assignment for a critical resource in the TeamViewer Client, allowing a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via the MSI rollback mechanism. This vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management. It is estimated that over 15,000 instances are affected.
Recommendations: For versions prior to 15.67, update to version 15.67 or later to resolve the issue. As a temporary workaround, consider restricting access to the Remote Management features: Backup, Monitoring, and Patch Management, until a patch is available. Avoid using the vulnerable MSI rollback mechanism in the affected TeamViewer Client versions.

Fix

LPE

Incorrect Default Permissions

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00588
CVE-2025-36537
ZDI-25-419

Affected Products

Teamviewer