CVE-2026-92369 PUBLISHED

Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation

Assigner: TV
Reserved: 16.09.2026 Published: 29.09.2026 Updated: 29.09.2026

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.3

Product Status

Vendor TeamViewer
Product Full Client
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 to 14.7.48855 (excl.)
  • affected from 13.2.0 to 13.2.36230 (excl.)
Vendor TeamViewer
Product Host
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 to 14.7.48855 (excl.)
  • affected from 13.2.0 to 13.2.36230 (excl.)

Solutions

Update to the latest version.

Credits

  • We thank Romain Igounet and Hugo Leclercq for the discovery and responsible disclosure. finder

References

Problem Types

  • CWE-367 Time-of-check time-of-use (TOCTOU) race condition CWE

Impacts

  • CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions