Local Privilege Escalation Vulnerability in TeamViewer Client Across Multiple Platforms
CVE-2026-19743
7.8HIGH
What is CVE-2026-19743?
An improperly validated path in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows local authenticated users with low privileges to write arbitrary files with elevated permissions. This vulnerability can be exploited by sending crafted IPC commands to the local service daemon, enabling attackers to manipulate file paths and achieve local privilege escalation, potentially compromising the system's integrity and security.
Affected Version(s)
Full Client Windows 15.0 < 15.82
Full Client Windows 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)
Full Client Windows 14.7.0 (Windows) < 14.7.48855 (Windows)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We thank Timo De Clercq & 0x_alibabas (Giuliano Sanfins) for the discovery and responsible disclosure.
