Race Condition Vulnerability in TeamViewer Full Client and Host
CVE-2025-44002

6.1MEDIUM

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
26 August 2025

What is CVE-2025-44002?

A race condition exists in the directory validation logic of TeamViewer Full Client and Host, allowing local non-admin users to exploit symbolic link manipulation. This exploitation can lead to the creation of arbitrary files with SYSTEM privileges, increasing the risk of denial-of-service conditions on Windows systems. Affected users should ensure they are running versions 15.69 or later to mitigate this security risk.

Affected Version(s)

Full Client Windows 11.0.0 < 15.69

Host Windows 11.0.0 < 15.69

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trend Micro Zero Day Initiative
.
CVE-2025-44002 : Race Condition Vulnerability in TeamViewer Full Client and Host