CVE-2025-0065

HIGH

TeamViewer <15.62 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a Windows system to elevate privileges via argument injection.

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 20.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-88
Status published
Products (10)
TeamViewer/Remote Full Client 11.0.0 - 11.0.259318
TeamViewer/Remote Full Client 12.0.0 - 12.0.259319
TeamViewer/Remote Full Client 13.0.0 - 13.2.36226
TeamViewer/Remote Full Client 14.0.0 - 14.7.48799
TeamViewer/Remote Full Client 15.0.0 - 15.62
TeamViewer/Remote Host 11.0.0 - 11.0.259318
TeamViewer/Remote Host 12.0.0 - 12.0.259319
TeamViewer/Remote Host 13.0.0 - 13.2.36226
TeamViewer/Remote Host 14.0.0 - 14.7.48799
TeamViewer/Remote Host 15.0.0 - 15.62
Published Jan 28, 2025
Tracked Since Feb 18, 2026