TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to the latest version.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | |
| Title | Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:39:53.082Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92369
No data.
Status : Received
Published: 2026-09-29T16:17:14.890
Modified: 2026-09-29T16:17:14.890
Link: CVE-2026-92369
No data.
OpenCVE Enrichment
No data.
Weaknesses