Impact
The vulnerability stems from improper validation of file paths in the local IPC service of TeamViewer Full Client and Host. An attacker with low‑privilege local access can craft IPC commands that manipulate pathname traversal, enabling writes of arbitrary files with elevated privileges such as NT AUTHORITY/SYSTEM on Windows or root on Linux and macOS. Exploiting this flaw permits a local user to overwrite critical binaries, configuration files, or inject executable content, thereby elevating their permissions to system level. The weakness is defined as a Classic Path Traversal (CWE-22).
Affected Systems
Affected are the TeamViewer Full Client and TeamViewer Host running on Windows, Linux, and macOS. Versions older than 15.82 are vulnerable; all builds prior to this release expose the IPC service to local users who can supply crafted commands.
Risk and Exploitability
The vulnerability scores 7.8 on the CVSS scale, indicating a high severity level, though no EPSS value is reported and it is not listed in the CISA KEV catalog. The attack is local; an authenticated user with ordinary privileges can trigger the exploit via the IPC interface. Because it requires local access and relies on IPC, remote exploitation is unlikely. Nonetheless, the potential impact of achieving SYSTEM or root warrants prompt remediation.
OpenCVE Enrichment