CVE-2026-92371 TeamViewer Linux 客户端路径校验不当漏洞
影响本地认证攻击者可诱导特权文件操作至非预期位置
TeamViewer Full Client and Host for Linux 15.82 之前版本的 Cloud Session Recording(CSR)功能存在路径校验不当漏洞。攻击者利用路径校验与后续文件访问之间的竞态条件(TOCTOU),可绕过校验。
影响范围
TeamViewer Full Client and Host for Linux 15.82 之前的版本;具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为路径校验不当(CWE-22/CWE-367 类),成因是 CSR 功能在验证文件路径与随后实际访问文件之间存在时间差。本地已认证攻击者可在该窗口内替换路径目标,使特权进程对非预期位置执行文件操作。
利用条件与风险
利用前提是攻击者需在目标 Linux 主机上拥有本地认证账户,并能在校验与访问之间赢得竞态窗口。实战中可导致特权文件被读取、覆盖或写入非预期目录,风险较高但利用条件较苛刻。
修复建议
建议升级至 TeamViewer Full Client and Host for Linux 15.82 或更高版本;临时缓解措施暂无公开信息。
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.