CVE-2026-92370 TeamViewer 客户端访问控制绕过漏洞
影响已认证远程攻击者可绕过权限设置执行被禁止的操作,可能导致远程代码执行
TeamViewer Full Client、Host 及相关模块在 Windows、Linux、macOS 平台上存在访问控制不当漏洞。攻击者在会话建立过程中修改受限功能的访问控制参数,从而绕过受害者配置的权限限制。该漏洞可能被用于执行受害者明确禁止的操作,并可能进一步导致目标系统上的远程代码执行。
影响范围
TeamViewer Full Client、Host 及相关受影响模块,涉及 Windows、Linux、macOS 平台;具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为访问控制不当(权限绕过)。成因在于会话建立阶段对访问控制参数的校验不充分,攻击者可篡改受限功能的权限参数。利用方式是已认证的远程攻击者发起会话时修改这些参数,从而执行被受害者配置明确拒绝的操作,并可能借此实现远程代码执行。
利用条件与风险
利用前提是攻击者需具备已认证的远程访问身份并能发起会话;实战中可绕过企业或用户的权限策略,风险较高,CVSS 评分 8.8。
修复建议
建议关注 TeamViewer 官方发布的安全更新并及时升级至修复版本;临时缓解措施包括限制可信设备接入、收紧会话权限策略并监控异常会话行为,具体方案以官方公告为准。
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim’s configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.