CVE 6.1 MEDIUM

Arbitrary File Creation via Symbolic Link leading to Denial-of-Service_CVE-2025-44002

6.1 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Description

Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows allows a local non-admin user to create arbitrary files with SYSTEM privileges, potentially leading to a denial-of-service condition, via symbolic link manipulation during directory verification.

Basic Information

ID CVE-2025-44002
Source TV
Published Aug 26, 2025 at 11:05

Affected Product

Vendor TeamViewer
Product Full Client
Version 11.0.0
Affected Versions TeamViewer Full Client 11.0.0
TeamViewer Host 11.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.