Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges.

The issue is detailed in TeamViewer security bulletin TV-2026-1008, published on August 26, 2026. It affects TeamViewer Remote, TeamViewer Tensor, and TeamViewer ONE deployments using vulnerable desktop client components.

CVE-2026-16444 stems from improper validation of file paths in TeamViewer Desktop Clients. The application fails to adequately sanitize filenames supplied by a remote peer before creating files on the receiving endpoint.

An authenticated participant in a TeamViewer remote session could exploit path-traversal sequences in filenames sent via the file-transfer function or the virtual file clipboard.

Multiple TeamViewer Vulnerability

Instead of placing a received file only in the intended download directory, the vulnerable client may write it to another location in the local file system. This arbitrary file-write condition can be abused to overwrite or place files in sensitive directories.

If an attacker can write a malicious executable, script, shortcut, or configuration file to a location later accessed by the user or another process, the attack could lead to remote code execution. The vulnerability has a CVSS score of 3.1 (7.5) and is rated Important by TeamViewer.

The exploitation is network-accessible but requires user interaction during a remote session. The flaw affects TeamViewer Full Client, Host, and QuickSupport versions earlier than 15.81.5 on Windows, macOS, and Linux.

Organizations using older supported and legacy releases must also apply the relevant updates. For Windows 7 and Windows 8 systems, affected TeamViewer components should be updated to version 15.64.7 or later.

TeamViewer 14 users should update Windows to 14.7.48833+ and Linux/macOS to 14.7.48838+; version 13 installations are also affected.

Windows systems need version 13.2.36229 or later, Linux systems need 13.2.153978 or later, and macOS systems need version 13.2.153981 or later. Remote-support platforms are attractive targets because they provide access to endpoints across corporate networks.

In this case, exploitation requires the attacker to be an authenticated participant in a TeamViewer session, reducing the likelihood of opportunistic attacks but increasing the risk of compromised accounts, malicious support personnel, or social-engineering operations.

An attacker could exploit the flaw using stolen TeamViewer credentials or an active session to deliver a payload via a seemingly legitimate file transfer.

The ability to write files outside expected directories could also support persistence, data destruction, or privilege-dependent code execution. TeamViewer said it is not aware of any public disclosure before the advisory or of evidence that CVE-2026-16444 has been exploited in the wild.

The company credited researchers Jamir0quai and sam91281 for responsibly reporting the vulnerability through its bug bounty program. Administrators should update all TeamViewer clients, hosts, and QuickSupport installations to version 15.81.5 or the latest available release.

Organizations should also review remote support session logs, restrict file transfers where they are not required, enforce multi-factor authentication, and monitor endpoints for unexpected files written to startup, application, or system paths.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks appeared first on Cyber Security News.