TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to the latest version.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | |
| Title | Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:39:53.082Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92369
No data.
Status : Received
Published: 2026-09-29T16:17:14.890
Modified: 2026-09-29T16:17:14.890
Link: CVE-2026-92369
No data.
OpenCVE Enrichment
No data.
Weaknesses