Description
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to the latest version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | |
| Title | Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:39:53.082Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92369
No data.
Status : Received
Published: 2026-09-29T16:17:14.890
Modified: 2026-09-29T16:17:14.890
Link: CVE-2026-92369
No data.
OpenCVE Enrichment
No data.
Weaknesses