CVE-2025-36537
Published: Jun 24, 2025
Modified: Jun 24, 2025
CVSS v3.1
7.0
Description
Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management.
| Vendor | Product | Versions |
|---|---|---|
TeamViewer | Full Client | affected 15.0.0 - < 15.67affected 14.0.0 - < 14.7.48809affected 13.0.0 - < 13.2.36227affected 12.0.0 - < 12.0.259325affected 11.0.0 - < 11.0.259324 |
TeamViewer | Host | affected 15.0.0 - < 15.67affected 14.0.0 - < 14.7.48809affected 13.0.0 - < 13.2.36227affected 12.0.0 - < 12.0.259325affected 11.0.0 - < 11.0.259324 |
TeamViewer | Full Client (Win7/8) | affected 15.0.0 - < 15.64.5 |
TeamViewer | Host (Win7/8) | affected 15.0.0 - < 15.64.5 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now