PT-2026-102662 · Teamviewer · Full – Cliente+1
CVE-2026-92369
·
Published
2026-09-29
·
Updated
2026-10-01
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamViewer Full Client and Host versions prior to 15.82
Description
A TOCTOU (Time-of-Check to Time-of-Use) race condition exists in the installer rollback mechanism on Windows. This occurs when a local low-privileged attacker replaces rollback backup files located in a user-writable temporary directory before an elevated installer restores them. A TOCTOU race condition is a software bug where a system checks the state of a resource before using it, but the state changes between the check and the use. Successful exploitation allows for privilege escalation to NT AUTHORITY/SYSTEM, provided the attacker times the race condition correctly during an installation or update rollback.
Recommendations
Update TeamViewer Full Client and Host to version 15.82 or later.
Fix
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Full – Cliente
Host