Sceawere
Vulnerability Detail
CVE-2026-19743UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TeamViewer IPC Local Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 9h ago
- Vendor
- TeamViewer
- Product
- Full Client
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T16:17:07.177Z",
"pubdate": "2026-09-29T16:17:07.177Z",
"executiveSummary": "This vulnerability involves improper path validation within the local Inter-Process Communication (IPC) service of TeamViewer Full Client and Host versions prior to 15.82.\nThe flaw allows a local, low-privileged authenticated user to perform arbitrary file writes with elevated privileges, specifically NT AUTHORITY\\SYSTEM on Windows and root on Linux/macOS.\nThe vulnerability is categorized as a local privilege escalation (LPE) issue resulting from insecure input handling in the service daemon's IPC interface.\nExploitation requires local access to the system and the ability to interact with the vulnerable IPC service via crafted commands.\nBy successfully manipulating the path validation logic, an attacker can overwrite critical system files or configurations to gain full administrative control over the underlying host.\nThis poses a critical security risk as it bypasses standard authorization boundaries to grant complete system-level compromise.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of file paths supplied through the IPC service interface.\nTeamViewer maintains a local service daemon that handles inter-process communication for various system management tasks. When a client process sends requests to this daemon, the service fails to verify or sanitize the paths provided in these IPC messages.\nA low-privileged local attacker can exploit this by crafting malicious IPC packets containing path traversal sequences or specific target paths. Because the service daemon operates with high privileges—NT AUTHORITY\\SYSTEM on Windows and root on Unix-based systems—it will execute file write operations on behalf of the attacker at these elevated levels.\nThe exploitation flow typically begins with the attacker identifying the IPC communication channel used by the TeamViewer service. Once the protocol structure is understood, the attacker sends a specially crafted command to the service daemon specifying a destination file path, such as a sensitive system file (e.g., binaries in System32 or system configuration files).\nThe daemon, failing to confirm whether the user has authorization to access or modify the target path, proceeds to perform the write operation. This effectively allows the attacker to replace legitimate system components, modify configuration files to disable security controls, or inject malicious code into startup scripts that execute under the service's elevated security context.\nThe affected versions include all TeamViewer Full Client and Host iterations prior to 15.82 across Windows, Linux, and macOS platforms.\nPost-exploitation, an attacker can achieve persistent system-wide compromise. By overwriting system binaries or service files, the attacker can guarantee execution of arbitrary code with SYSTEM or root privileges upon the next system boot or service restart. This eliminates the need for further exploitation of the IPC interface once the payload is placed successfully. The lack of network exposure means this attack is limited to local vectors, yet it remains highly dangerous in environments where multiple users share system access, such as terminal servers or workstations with guest accounts."
}