PT-2025-26744 · Teamviewer · Teamviewer
0X_Alibabas
+1
·
Published
2025-06-24
·
Updated
2026-03-01
·
CVE-2025-36537
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
TeamViewer versions prior to 15.67
Description:
The issue is related to an incorrect permission assignment for a critical resource in the TeamViewer Client, allowing a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via the MSI rollback mechanism. This vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management. It is estimated that over 15,000 instances are affected.
Recommendations:
For versions prior to 15.67, update to version 15.67 or later to resolve the issue. As a temporary workaround, consider restricting access to the Remote Management features: Backup, Monitoring, and Patch Management, until a patch is available. Avoid using the vulnerable MSI rollback mechanism in the affected TeamViewer Client versions.
Fix
LPE
Incorrect Default Permissions
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teamviewer