CVE-2025-41421

MEDIUM

TeamViewer <15.70 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.

Scores

CVSS v3 4.7
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-59
Status published
Products (2)
TeamViewer/Full Client 11.0.0 - 15.70
TeamViewer/Host 11.0.0 - 15.70
Published Oct 01, 2025
Tracked Since Feb 18, 2026