Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management.
History

Tue, 24 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276

Tue, 24 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732

Tue, 24 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management.
Title Incorrect Permission Assignment for Critical Resource in TeamViewer Remote Management
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published: 2025-06-24T14:24:08.394Z

Updated: 2025-06-24T15:31:17.734Z

Reserved: 2025-04-30T08:08:15.966Z

Link: CVE-2025-36537

cve-icon Vulnrichment

Updated: 2025-06-24T14:46:04.928Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-24T15:15:24.453

Modified: 2025-06-26T18:58:14.280

Link: CVE-2025-36537

cve-icon Redhat

No data.