Incorrect Permission Assignment for Critical Resource in TeamViewer Remote Management
Vulnerability Description
Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only applies to the Remote Management features: Backup, Monitoring, and Patch Management.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-36537
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Giuliano Sanfins (0x_alibabas) from SiDi, working with Trend Micro Zero Day Initiativ
More from TeamViewer
View All →Affected Vendor
TeamViewer
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.