Sceawere
Vulnerability Detail
CVE-2026-92368UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TeamViewer Heap Buffer Overflow Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 9h ago
- Vendor
- TeamViewer
- Product
- Full Client
- Attack Type
- CWE-122 Heap-based buffer overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T16:17:14.753Z",
"pubdate": "2026-09-29T16:17:14.753Z",
"executiveSummary": "This vulnerability is identified as a heap-based buffer overflow affecting TeamViewer Full Client and Host versions prior to 15.82 on Linux and macOS platforms.\nThe flaw resides in the processing logic for .tvs session recording files, specifically during the decompression phase.\nA size mismatch between the compressed data and the allocated heap buffer leads to out-of-bounds heap writes, which can be weaponized by an attacker.\nSuccessful exploitation requires user interaction; the attacker must convince the victim to open a specially crafted .tvs file using the 'Play or convert recorded session' feature.\nThe primary impact of this vulnerability is arbitrary code execution, granting the attacker the full privileges of the user currently executing the TeamViewer application.\nDue to the nature of code execution, this flaw poses a high security risk, potentially allowing for system compromise, data theft, or lateral movement within the environment.\nThe vulnerability does not require prior authentication to the system, but relies on social engineering to induce the user to process the malicious file.",
"technicalDetails": "The root cause of this vulnerability is a logic error during the decompression of .tvs session recording files within TeamViewer. When the application attempts to process these files, it performs a decompression routine that fails to properly validate the relationship between the expected decompressed data size and the actual size of the allocated memory buffer on the heap.\nSpecifically, the vulnerability manifests as a heap-based buffer overflow. If a malicious .tvs file specifies a decompressed size that exceeds the destination buffer's capacity, the decompression engine continues writing data beyond the allocated boundaries. This triggers an out-of-bounds heap write.\nThe attack flow begins when an attacker distributes a weaponized .tvs file to a target user. The victim is then tricked into utilizing the 'Play or convert recorded session' functionality within the TeamViewer Full Client or Host. As the application initializes the file parsing and decompression sequence, the malicious input triggers the buffer overflow.\nBy carefully crafting the malicious .tvs file, an attacker can overwrite adjacent heap metadata or function pointers. This heap grooming allows the attacker to redirect the application's execution flow. By hijacking the control flow, the attacker can execute arbitrary shellcode or perform Return-Oriented Programming (ROP) to bypass system protections such as DEP/NX, eventually achieving code execution with the context and privileges of the logged-in user.\nAffected software includes TeamViewer Full Client and TeamViewer Host on Linux and macOS platforms in all versions prior to 15.82. The vulnerability is triggered locally on the host machine upon user-initiated interaction with the file, meaning it does not rely on active network exploitation, but rather the processing of a malicious file payload.\nSuccessful exploitation results in full code execution in the context of the user process. Depending on the user's privilege level, this may grant the attacker extensive access to the local system, including the ability to install persistent malware, exfiltrate sensitive data, or pivot to other systems on the network. There are no authentication requirements to execute this attack, as the application logic itself is inherently vulnerable when processing untrusted inputs from the user interface."
}