TeamViewer has urged users to update its software after disclosing 5 vulnerabilities in its client and host products. The company recommends installing the latest available version as soon as possible.
The most severe issue, CVE-2026-92370, is an access control bypass in TeamViewer Full Client and Host for Windows, Linux, and macOS. TeamViewer says remote attackers could use it to perform unauthorized actions that lead to remote code execution on targeted systems.
The other 4 flaws are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use race condition (CVE-2026-92369), and improper path validation (CVE-2026-92371). The company says local attackers could use these issues to gain code execution with the current user's privileges or escalate privileges to NT AUTHORITY/SYSTEM or root.
TeamViewer says version 15.82 addresses the vulnerabilities, along with supported maintenance and legacy releases. The company said it is not aware of public disclosure or active exploitation in the wild.
Comments
0No comments yet. Be the first to comment.