Sceawere
Vulnerability Detail
CVE-2026-92369UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TeamViewer Installer TOCTOU Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 9h ago
- Vendor
- TeamViewer
- Product
- Full Client
- Attack Type
- CWE-367 Time-of-check time-of-use (TOCTOU) race condition
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-29T16:17:14.890Z",
"pubdate": "2026-09-29T16:17:14.890Z",
"executiveSummary": "This vulnerability is identified as a Time-of-Check to Time-of-Use (TOCTOU) race condition within the installer rollback mechanism of TeamViewer Full Client and Host for Windows prior to version 15.82.\nThe flaw resides in the handling of backup files during an installer rollback procedure. Because the restoration process involves files residing in a directory with low-privileged write access, an authenticated local attacker can manipulate these files to execute arbitrary code with elevated permissions.\nSuccessful exploitation allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\\SYSTEM, effectively granting full control over the compromised system.\nThe attack is contingent upon the attacker's ability to precisely time the replacement of backup files during the narrow execution window of the rollback process. This vulnerability poses a significant security risk, as it permits lateral movement and full system compromise from an unprivileged local user context.",
"technicalDetails": "The vulnerability originates from an insecure file handling pattern during the rollback phase of the TeamViewer installer. The installer stores backup files within a temporary directory that possesses insecure permissions, allowing standard local users to modify the contents of the directory.\nThe root cause is a classic TOCTOU race condition where the elevated installer process verifies or prepares to restore a backup file, but the file content can be swapped by an attacker after the check but before the file is actually moved or executed by the privileged installer process.\nAttack flow: First, an attacker initiates or monitors an installation or update procedure for TeamViewer. During this process, the installer generates temporary rollback files in a user-accessible directory. Second, the attacker must proactively monitor the filesystem to identify when these backup files are written to the temporary location. Third, utilizing the TOCTOU window, the attacker replaces the legitimate, benign backup file with a malicious payload (e.g., a malicious DLL or executable) before the elevated installer process invokes the restoration logic.\nBecause the installation/update service runs with NT AUTHORITY\\SYSTEM privileges, the restoration logic blindly trusts the contents of the temporary directory. When the installer executes the final move or restoration operation, it executes or incorporates the attacker-supplied malicious file with system-level privileges.\nThis exploit bypasses standard Windows access controls because the operation is performed by a high-integrity process that has been tricked into interacting with an attacker-controlled file path. The impact of this vulnerability is total system compromise, as the injected code operates within the context of the system account, allowing for the installation of persistence mechanisms, credential harvesting, or full data exfiltration.\nAffected products include TeamViewer Full Client and Host on Windows prior to version 15.82. The vulnerability requires local access to the filesystem to perform the file replacement, meaning there is no remote network exposure, but the risk remains critical in multi-user environments or systems where unauthorized local users can perform file system operations."
}