TOCTOU Race Condition Vulnerability in TeamViewer Full Client and Host
CVE-2026-92369
What is CVE-2026-92369?
The TeamViewer Full Client and Host versions prior to 15.82 for Windows are affected by a time-of-check-to-time-of-use (TOCTOU) race condition in the installer rollback mechanism. This vulnerability allows a local attacker with low privileges to exploit the race condition to replace the rollback backup files stored in a user-writable temporary directory. By successfully timing the attack and initiating a rollback during the installation or update process, the attacker can gain elevated privileges, potentially achieving access to NT AUTHORITY/SYSTEM. It is crucial for users to update to the latest version to mitigate this security risk.
Affected Version(s)
Full Client Windows 15.0 < 15.82
Full Client Windows 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)
Full Client Windows 14.7.0 < 14.7.48855
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
