Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.
References
Configurations
No configuration.
History
01 Oct 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-01 14:15
Updated : 2025-10-02 19:11
NVD link : CVE-2025-41421
Mitre link : CVE-2025-41421
CVE.ORG link : CVE-2025-41421
JSON object : View
Products Affected
No product.
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')