« Volver al listado

CVE-2025-41421

Estado: AplazadaMedia (4.7)—

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-41421",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-41421",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-01T13:59:12.175007Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@teamviewer.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@teamviewer.com",
      "affectedData": [
        {
          "vendor": "TeamViewer",
          "product": "Full Client",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0",
              "lessThan": "15.70",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TeamViewer",
          "product": "Host",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0",
              "lessThan": "15.70",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-10-01T14:15:39.953",
  "references": [
    {
      "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1004/",
      "source": "psirt@teamviewer.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@teamviewer.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information."
    }
  ],
  "lastModified": "2026-06-17T09:22:50.700",
  "sourceIdentifier": "psirt@teamviewer.com"
}