Impact
An authenticated participant in a remote TeamViewer session can write files to arbitrary locations on the local file system by exploiting improper neutralization of path traversal sequences in file transfer or virtual file clipboard operations. The flaw allows the attacker to create or overwrite files with the privileges of the affected user, potentially leading to execution of malicious code. This vulnerability is an instance of path traversal (CWE‑73).
Affected Systems
TeamViewer Desktop Clients - Full Client, Host, QuickSupport, and Portable - running on Windows 7 or Windows 8, and on newer Windows builds bundled with v13 or v14; Linux clients built with v13 or v14; macOS clients built with v13 or v14 - all versions prior to 15.81.5 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the overall exploitation likelihood may be moderate but not negligible. Attackers require authenticated remote session access and can exploit the flaw through standard file transfer or virtual clipboard features, meaning that any user who allows a remote participant can be impacted. The risk is amplified in environments where file system permissions are lax or where the client is granted broad access rights. Given the high severity score and the ability to write arbitrary files, organizations should treat this as a significant security concern until mitigated.
OpenCVE Enrichment