TeamViewer Patches Five Vulnerabilities Affecting Remote Access Clients and Hosts

Remote support workstation representing TeamViewer security updates

Written by

in

TeamViewer has issued security updates for five vulnerabilities affecting its Full Client and Host software. The company recommends upgrading to version 15.82 or the applicable supported maintenance release and says it is not aware of public exploit code or active exploitation.

The flaws affect access control and local privilege boundaries

The highest-severity issue, CVE-2026-92370, is an improper access-control weakness that could let a remote threat actor perform unauthorized actions during a session, potentially leading to code execution. The update also addresses path traversal, a heap-based buffer overflow, a time-of-check to time-of-use race condition and improper path validation. Depending on the flaw and platform, exploitation could enable code execution or privilege escalation to SYSTEM or root.

Remote-support software deserves priority handling

Because remote administration tools are designed to cross normal physical and network boundaries, vulnerable installations should be inventoried and updated quickly. Security teams should confirm versions on both attended clients and unattended hosts, review approved-account lists, remove obsolete deployments and monitor for unexpected sessions. The absence of known exploitation should not be treated as proof of low operational risk. SectechMedia’s guide to asset inventory and configuration management outlines how to track exposed software and verify remediation.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *