CVE-2025-41421: Privilege Escalation via Symbolic Link Spoofing in TeamViewer Client
Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may result in unauthorized access to sensitive information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41421?
CVE-2025-41421 has a medium severity level due to the potential for privilege escalation.
How do I fix CVE-2025-41421?
To fix CVE-2025-41421, upgrade to TeamViewer versions 15.70 or later.
What kind of access is required to exploit CVE-2025-41421?
CVE-2025-41421 can be exploited by an attacker with local, unprivileged access to a vulnerable device.
Which software versions are affected by CVE-2025-41421?
CVE-2025-41421 affects TeamViewer Remote and Tensor versions prior to 15.70.
What is the risk of not addressing CVE-2025-41421?
Not addressing CVE-2025-41421 could allow an attacker to escalate privileges and execute malicious actions on the system.