Impact
TeamViewer Full Client and Host for Linux and macOS contain a heap‑based buffer overflow in the handling of .tvs session recording files. During decompression, a size mismatch creates an out‑of‑bounds write on the heap. If an attacker supplies a specially crafted recording and convinces a user to open it via the “Play or convert recorded session…” feature, the user’s privileges can be exploited to execute arbitrary code.
Affected Systems
Linux and macOS users running TeamViewer Full Client or Host prior to version 15.82 are affected. The vulnerability exists in both the client and the host components for these platforms.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. EPSS data is not available, making it unclear how frequently the exploit has been observed. The vulnerability is not listed in the CISA KEV catalog, but the possibility of exploitation remains through user‑initiated local attack. An attacker must convince a logged‑in user to open a malicious session recording; once opened, the buffer overflow allows code execution with the current user’s privileges.
OpenCVE Enrichment