PT-2025-26744 · Teamviewer · Teamviewer

0X_Alibabas

+1

·

Published

2025-06-24

·

Updated

2026-03-01

·

CVE-2025-36537

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TeamViewer versions prior to 15.67
Description: The issue is related to an incorrect permission assignment for a critical resource in the TeamViewer Client, allowing a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via the MSI rollback mechanism. This vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management. It is estimated that over 15,000 instances are affected.
Recommendations: For versions prior to 15.67, update to version 15.67 or later to resolve the issue. As a temporary workaround, consider restricting access to the Remote Management features: Backup, Monitoring, and Patch Management, until a patch is available. Avoid using the vulnerable MSI rollback mechanism in the affected TeamViewer Client versions.

Fix

LPE

Incorrect Default Permissions

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2026-00588
CVE-2025-36537
ZDI-25-419

Affected Products

Teamviewer