TeamViewer Urges Customers to Patch Five High-Severity Vulnerabilities
Remote access software company TeamViewer is urging customers to immediately update its client and host software after disclosing five high-severity vulnerabilities affecting Windows, Linux, and macOS.
TeamViewer flaw could enable remote code execution
The most severe issue is a remote session access-control bypass tracked as CVE-2026-92370.
The improper access-control vulnerability affects TeamViewer Full Client and Host software. A remote threat actor could exploit the flaw to perform unauthorized actions that may lead to remote code execution on a targeted system.
Five TeamViewer vulnerabilities fixed
The other four security issues addressed by TeamViewer are:
- Path traversal, tracked as CVE-2026-19743.
- Heap-based buffer overflow, tracked as CVE-2026-92368.
- Time-of-check time-of-use (TOCTOU) race condition, tracked as CVE-2026-92369.
- Improper path validation, tracked as CVE-2026-92371.
According to TeamViewer, these vulnerabilities could allow a local attacker to remotely execute code with the privileges of the current user or escalate privileges to NT AUTHORITY\SYSTEM or root.
TeamViewer releases version 15.82 security update
“TeamViewer strongly recommends that all users update to the latest available version as soon as possible,” the company warned in a security advisory.
TeamViewer said it has released a security update addressing multiple vulnerabilities affecting TeamViewer Full Client, Host, and related services.
The vulnerabilities have been fixed in TeamViewer client version 15.82, as well as supported maintenance and legacy releases.
There is currently no evidence that exploit code has been publicly released or that the vulnerabilities are being actively exploited.
“TeamViewer is not aware of any public disclosure or actual exploitation,” the company added.
TeamViewer has been abused by cybercriminals
TeamViewer remote access and desktop-sharing software is widely used for its simplicity and functionality. However, cybercriminals, including ransomware groups, have also abused the software to gain remote access to victim systems and deploy malware and other malicious tools.
Over the past decade, TeamViewer has disclosed several breaches involving corporate networks. The first incident involved Chinese attackers using Winnti backdoor malware in 2016 and was disclosed in May 2019.
A second incident affected an internal corporate network and was disclosed two years ago. Days later, the breach was linked to the Russian state-sponsored hacking group tracked as Midnight Blizzard, also known as APT29, Nobelium, and Cozy Bear.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



