Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-36537
TeamViewer Remote vulnerability analysis and mitigation

Overview

CVE-2025-36537 is an Incorrect Permission Assignment for Critical Resource vulnerability in the TeamViewer Client (Full and Host) for TeamViewer Remote and Tensor on Windows that allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges. The flaw specifically affects the Remote Management features — Backup, Monitoring, and Patch Management — and is exploited by leveraging the MSI rollback mechanism. Affected versions include TeamViewer Full Client and Host prior to version 15.67 (and several older release branches: 11.x before 11.0.259324, 12.x before 12.0.259325, 13.x before 13.2.36227, 14.x before 14.7.48809, and Win7/8 builds before 15.64.5). It was published on June 24, 2025, and carries a CVSS v3.1 base score of 7.0 (High) (TeamViewer Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-276 (Incorrect Default Permissions), where files or directories associated with TeamViewer's Remote Management features are assigned overly permissive access controls (TeamViewer Advisory). A local low-privileged attacker can abuse the Windows Installer (MSI) rollback mechanism — which runs with SYSTEM privileges — to delete arbitrary files on the system by manipulating rollback scripts or temporary files that the unprivileged user can influence. Exploitation requires local access and low privileges, but no user interaction, and the attack complexity is rated High, indicating that specific conditions or race conditions must be met (ENISA EUVD). The Zero Day Initiative also published an advisory (ZDI-25-419) covering this vulnerability (ZDI Advisory).

Impact

Successful exploitation allows a local unprivileged attacker to delete arbitrary files with SYSTEM-level privileges, which can lead to denial of service (system instability or application failure), privilege escalation (by deleting protected files to enable DLL hijacking or similar techniques), and potential integrity compromise of critical system resources (TeamViewer Advisory, GBHackers). The CVSS v3.1 scoring reflects High impacts across confidentiality, integrity, and availability. The scope is limited to the local system, but arbitrary file deletion with SYSTEM rights can be chained with other techniques for full system compromise (CyberInsider).

Exploitability

As of the disclosure date (June 24, 2025), no public proof-of-concept exploit code or in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (Feedly Intelligence). The High attack complexity rating further reduces the likelihood of widespread exploitation, as specific conditions must be met to trigger the MSI rollback mechanism. Nessus plugin 241521 is available for detection (Tenable).

Exploitation steps

  1. Reconnaissance: Identify a Windows system running a vulnerable version of TeamViewer Client (Full or Host) prior to version 15.67 with Remote Management features (Backup, Monitoring, or Patch Management) enabled.
  2. Local Access: Obtain a low-privileged local user account on the target system — no administrative rights are required.
  3. Identify MSI Rollback Artifacts: Locate temporary files or rollback scripts created by the TeamViewer MSI installer in directories where the unprivileged user has write access, due to incorrect permission assignments on critical resources.
  4. Manipulate Rollback Target: Replace or create a symbolic link or junction point in the writable directory to redirect the MSI rollback operation to target an arbitrary file (e.g., a critical system file or security tool binary).
  5. Trigger MSI Rollback: Initiate or wait for a TeamViewer installation, update, or repair operation that triggers the MSI rollback mechanism, which executes with SYSTEM privileges.
  6. Achieve Arbitrary File Deletion: The MSI rollback process, running as SYSTEM, deletes the attacker-specified file, enabling denial of service or enabling further privilege escalation via follow-on techniques such as DLL hijacking (TeamViewer Advisory, ZDI Advisory).

Indicators of compromise

  • File System: Unexpected deletion of critical system files or security tool binaries; presence of symbolic links or junction points in TeamViewer temporary or installation directories pointing to unrelated system paths.
  • Logs: Windows Installer (MSI) event logs (Event ID 1033, 1034, or 11708) showing TeamViewer installation/repair/rollback activity initiated by a low-privileged user account; Windows Security audit logs showing SYSTEM-level file deletion events on non-TeamViewer paths.
  • Process: msiexec.exe running under SYSTEM context initiated by or correlated with a low-privileged user session; unusual child processes or file operations originating from msiexec.exe targeting non-standard directories.
  • Network: No specific network IOCs identified, as this is a local privilege escalation vulnerability (TeamViewer Advisory).

Mitigation and workarounds

TeamViewer has released patched versions addressing this vulnerability: Full Client and Host version 15.67 or later for current Windows builds, 15.64.5 for Windows 7/8 builds, 14.7.48809 for version 14.x, 13.2.36227 for version 13.x, 12.0.259325 for version 12.x, and 11.0.259324 for version 11.x (TeamViewer Advisory). Organizations should prioritize upgrading to the latest patched release. As a temporary workaround, disabling the affected Remote Management features (Backup, Monitoring, and Patch Management) reduces the attack surface until patching is feasible (SecurityOnline).

Community reactions

Security media outlets including GBHackers, CyberSecurityNews, CyberInsider, and The Hacker News (weekly recap) covered the vulnerability shortly after disclosure, highlighting the SYSTEM-level file deletion risk (GBHackers, CyberSecurityNews). Heise (German tech outlet) also reported on the privilege escalation risk (Heise). The Zero Day Initiative published advisory ZDI-25-419, lending additional credibility to the technical findings (ZDI Advisory). Community reaction on Bluesky and Infosec.exchange noted the vulnerability but did not indicate widespread alarm, consistent with the High attack complexity and local-only attack vector.

Additional resources


SourceThis report was generated using AI

Related TeamViewer Remote vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12703HIGH8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJul 29, 2026
CVE-2025-0065HIGH7.8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJan 28, 2025
CVE-2026-23572HIGH7.2
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesFeb 05, 2026
CVE-2025-36537HIGH7
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJun 24, 2025
CVE-2024-6053MEDIUM4.3
  • TeamViewer Remote logoTeamViewer Remote
  • teamviewer
NoYesAug 28, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management