CVE-2025-0065 is a high-severity vulnerability affecting TeamViewer Clients for Windows prior to version 15.62. It involves improper neutralization of argument delimiters in the TeamViewer_service.exe component, enabling a local unprivileged attacker to achieve privilege escalation through argument injection. The vulnerability has a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TeamViewer | Remote Full Client | >= 11.0.0, < 11.0.259318, >= 12.0.0, < 12.0.259319, >= 13.0.0, < 13.2.36226, >= 14.0.0, < 14.7.48799, >= 15.0.0, < 15.62CNA affecteddefault unaffected | |
| TeamViewer | Remote Host | >= 11.0.0, < 11.0.259318, >= 12.0.0, < 12.0.259319, >= 13.0.0, < 13.2.36226, >= 14.0.0, < 14.7.48799, >= 15.0.0, < 15.62CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.