Incorrect permission assignment for critical resource in TeamViewer Remote Full Client for Windows and TeamViewer Remote Host for Windows - CVE-2025-36537
Published: June 24, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect permission assignment for critical resource within the Remote Management features: Backup, Monitoring, and Patch Management. A local unprivileged user can delete arbitrary files with SYSTEM privileges by leveraging the MSI rollback mechanism and escalate privileges on the system.
Affected software
TeamViewer Remote Host for Windows
How to mitigate CVE-2025-36537
TeamViewer Remote Host for Windows - addressed in versions 11.0.259324, 12.0.259325, 13.2.36226, 14.7.48809, 15.64.5, 15.67