PT-2025-1303 · Teamviewer · Teamviewer
Published
2025-01-28
·
Updated
2025-02-05
·
CVE-2025-0065
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamViewer versions prior to 15.62
Description
The issue is related to improper neutralization of argument delimiters in the TeamViewer service.exe component, allowing an attacker with local unprivileged access on a Windows system to elevate privileges via argument injection. This vulnerability affects TeamViewer Clients for Windows prior to version 15.62. There is no mention of the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
Update to version 15.62 or later to address this issue. As a temporary workaround, consider disabling the
TeamViewer service.exe component until a patch is available. Restrict access to the vulnerable TeamViewer service.exe component to minimize the risk of exploitation. Avoid using the vulnerable component until the issue is resolved. At the moment, there is no information about additional mitigation measures.Fix
LPE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamviewer