CVE-2026-92369

LOWCVSS 7.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-30: 309-30
Referenced assets1 URL
Full discourse3 posts
  • Juan F Gallego@jfernandogg

    CVE-2026-92370 (CVSS 8.8) en TeamViewer Full Client/Host: improper access control — un atacante autenticado remoto salta permisos de sesión y llega a RCE. Advisory TV-2026-1010 (29 sep); vendor urgió actualizar "as soon as possible". También High: path traversal CVE-2026-19743 (LPE SYSTEM/root), heap overflow CVE-2026-92368 (RCE vía .tvs recording en Linux/macOS), TOCTOU installer CVE-2026-92369, path validation CSR CVE-2026-92371. Fix: 15.82 (+ legacy 15.64.8 / 14.7.48855 / 13.2.*). Sin evidencia de explotación activa ni PoC público —igual urge por el abuso histórico de TeamViewer en ransomware. Despliega flota hoy.

    0001047
    341 followersView on X
  • Autumn Good@autumn_good_35

    CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371 Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2026-1010/

    00010362
    7.2K followersView on X
  • Orion84@Orion84x

    Why it matters: Five flaws in Full Client and Host on Windows, Linux, and macOS. Highest is CVE-2026-92370, a remote session access-control bypass that can lead to RCE. Others can escalate to SYSTEM or root (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371).

    0000028
    20 followersView on X

Explore more