
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36537 is an Incorrect Permission Assignment for Critical Resource vulnerability in the TeamViewer Client (Full and Host) for TeamViewer Remote and Tensor on Windows that allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges. The flaw specifically affects the Remote Management features — Backup, Monitoring, and Patch Management — and is exploited by leveraging the MSI rollback mechanism. Affected versions include TeamViewer Full Client and Host prior to version 15.67 (and several older release branches: 11.x before 11.0.259324, 12.x before 12.0.259325, 13.x before 13.2.36227, 14.x before 14.7.48809, and Win7/8 builds before 15.64.5). It was published on June 24, 2025, and carries a CVSS v3.1 base score of 7.0 (High) (TeamViewer Advisory, ENISA EUVD).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-276 (Incorrect Default Permissions), where files or directories associated with TeamViewer's Remote Management features are assigned overly permissive access controls (TeamViewer Advisory). A local low-privileged attacker can abuse the Windows Installer (MSI) rollback mechanism — which runs with SYSTEM privileges — to delete arbitrary files on the system by manipulating rollback scripts or temporary files that the unprivileged user can influence. Exploitation requires local access and low privileges, but no user interaction, and the attack complexity is rated High, indicating that specific conditions or race conditions must be met (ENISA EUVD). The Zero Day Initiative also published an advisory (ZDI-25-419) covering this vulnerability (ZDI Advisory).
Successful exploitation allows a local unprivileged attacker to delete arbitrary files with SYSTEM-level privileges, which can lead to denial of service (system instability or application failure), privilege escalation (by deleting protected files to enable DLL hijacking or similar techniques), and potential integrity compromise of critical system resources (TeamViewer Advisory, GBHackers). The CVSS v3.1 scoring reflects High impacts across confidentiality, integrity, and availability. The scope is limited to the local system, but arbitrary file deletion with SYSTEM rights can be chained with other techniques for full system compromise (CyberInsider).
As of the disclosure date (June 24, 2025), no public proof-of-concept exploit code or in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (Feedly Intelligence). The High attack complexity rating further reduces the likelihood of widespread exploitation, as specific conditions must be met to trigger the MSI rollback mechanism. Nessus plugin 241521 is available for detection (Tenable).
msiexec.exe running under SYSTEM context initiated by or correlated with a low-privileged user session; unusual child processes or file operations originating from msiexec.exe targeting non-standard directories.TeamViewer has released patched versions addressing this vulnerability: Full Client and Host version 15.67 or later for current Windows builds, 15.64.5 for Windows 7/8 builds, 14.7.48809 for version 14.x, 13.2.36227 for version 13.x, 12.0.259325 for version 12.x, and 11.0.259324 for version 11.x (TeamViewer Advisory). Organizations should prioritize upgrading to the latest patched release. As a temporary workaround, disabling the affected Remote Management features (Backup, Monitoring, and Patch Management) reduces the attack surface until patching is feasible (SecurityOnline).
Security media outlets including GBHackers, CyberSecurityNews, CyberInsider, and The Hacker News (weekly recap) covered the vulnerability shortly after disclosure, highlighting the SYSTEM-level file deletion risk (GBHackers, CyberSecurityNews). Heise (German tech outlet) also reported on the privilege escalation risk (Heise). The Zero Day Initiative published advisory ZDI-25-419, lending additional credibility to the technical findings (ZDI Advisory). Community reaction on Bluesky and Infosec.exchange noted the vulnerability but did not indicate widespread alarm, consistent with the High attack complexity and local-only attack vector.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."