Privilege Escalation in TeamViewer Full Client and Host for Windows
CVE-2025-41421

4.7MEDIUM

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
1 October 2025

What is CVE-2025-41421?

This vulnerability arises from inadequate handling of symbolic links in TeamViewer Full Client and Host for Windows versions prior to 15.70. An attacker with local, unprivileged access can exploit this flaw by manipulating the update file path, potentially leading to privilege escalation. Such an exploit may allow unauthorized access to sensitive data on the compromised system, especially if adequate malware protection measures are not in place.

Affected Version(s)

Full Client Windows 11.0.0 < 15.70

Host Windows 11.0.0 < 15.70

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@TwoSevenOneT (X) with ZeroSalarium.com
.
CVE-2025-41421 : Privilege Escalation in TeamViewer Full Client and Host for Windows