#VU111865 Incorrect permission assignment for critical resource in TeamViewer Remote Full Client for Windows and TeamViewer Remote Host for Windows - CVE-2025-36537
Published: June 24, 2025
TeamViewer Remote Full Client for Windows
TeamViewer Remote Host for Windows
TeamViewer
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect permission assignment for critical resource within the Remote Management features: Backup, Monitoring, and Patch Management. A local unprivileged user can delete arbitrary files with SYSTEM privileges by leveraging the MSI rollback mechanism and escalate privileges on the system.