{"id":"CVE-2026-92369","title":"TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism","summary":"TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary …","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-367"],"vendor":"TeamViewer","product":"Full Client","affected":["full_client >= 15.0 < 15.82","full_client >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)","full_client >= 14.7.0 < 14.7.48855","full_client >= 13.2.0 < 13.2.36230","Host >= 15.0 < 15.82","Host >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)","Host >= 14.7.0 < 14.7.48855","Host >= 13.2.0 < 13.2.36230"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:14.890","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92369","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","label":"psirt@teamviewer.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.270Z","slug":"CVE-2026-92369","body":"## Overview\n\nTeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}