TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. (CVE-2026-92369)
TeamViewer Full Client and Host versions prior to 15.82 on Windows have a time-of-check to time-of-use (TOCTOU) race condition in the installer rollback mechanism. This vulnerability allows a local low-privileged attacker to replace rollback backup files in a user-writable temporary directory before they are restored by an elevated installer, potentially escalating privileges to NT AUTHORITY/SYSTEM. Exploitation requires precise timing of the race condition during an installation or update rollback.
AI Analysis
Technical Summary
CVE-2026-92369 describes a TOCTOU race condition in the installer rollback mechanism of TeamViewer Full Client and Host on Windows versions prior to 15.82. A local attacker with low privileges can exploit this vulnerability by replacing rollback backup files stored in a user-writable temporary directory before the elevated installer restores them. Successful exploitation results in privilege escalation to NT AUTHORITY/SYSTEM. The attack requires timing the race condition during an installation or update rollback process.
Potential Impact
If exploited, this vulnerability allows a local low-privileged user to escalate their privileges to NT AUTHORITY/SYSTEM, granting full system control. This can lead to complete compromise of the affected system. However, exploitation requires local access and precise timing of the race condition during rollback.
Mitigation Recommendations
A fix is available in TeamViewer version 15.82. Users should update to version 15.82 or later to remediate this vulnerability. No other mitigation guidance is provided.
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. (CVE-2026-92369)
Description
TeamViewer Full Client and Host versions prior to 15.82 on Windows have a time-of-check to time-of-use (TOCTOU) race condition in the installer rollback mechanism. This vulnerability allows a local low-privileged attacker to replace rollback backup files in a user-writable temporary directory before they are restored by an elevated installer, potentially escalating privileges to NT AUTHORITY/SYSTEM. Exploitation requires precise timing of the race condition during an installation or update rollback.
CVSS v3.1
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92369 describes a TOCTOU race condition in the installer rollback mechanism of TeamViewer Full Client and Host on Windows versions prior to 15.82. A local attacker with low privileges can exploit this vulnerability by replacing rollback backup files stored in a user-writable temporary directory before the elevated installer restores them. Successful exploitation results in privilege escalation to NT AUTHORITY/SYSTEM. The attack requires timing the race condition during an installation or update rollback process.
Potential Impact
If exploited, this vulnerability allows a local low-privileged user to escalate their privileges to NT AUTHORITY/SYSTEM, granting full system control. This can lead to complete compromise of the affected system. However, exploitation requires local access and precise timing of the race condition during rollback.
Mitigation Recommendations
A fix is available in TeamViewer version 15.82. Users should update to version 15.82 or later to remediate this vulnerability. No other mitigation guidance is provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gc52-c427-xf67
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92369"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc27c3680226ef6846f81c
Added to database: 09/29/2026, 21:04:03 UTC
Last enriched: 09/29/2026, 21:18:19 UTC
Last updated: 09/30/2026, 03:38:52 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.