PT-2026-82046 · Teamviewer · Teamviewer Full Client+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamViewer Full Client and Host for Linux versions prior to 15.81.5
Description
A command injection issue exists that allows a remote attacker to execute arbitrary commands with the privileges of the current user. This occurs when a user clicks a specially crafted URL sent via the out-of-session chat feature. Command injection is a flaw where an application allows an attacker to execute unauthorized system commands on the host operating system.
Recommendations
Update TeamViewer Full Client and Host for Linux to version 15.81.5 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamviewer Full Client
Teamviewer Host