CVE-2025-41421

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.
Configurations

No configuration.

History

01 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-01 14:15

Updated : 2025-10-02 19:11


NVD link : CVE-2025-41421

Mitre link : CVE-2025-41421

CVE.ORG link : CVE-2025-41421


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')