# TeamViewer 修复五个漏洞，其中包括可通过远程会话执行代码的缺陷

> TeamViewer 安全公告 TV-2026-1010 涵盖 Windows、Linux 和 macOS 客户端中的五个漏洞，已在 15.82 版修复。目前已知的情况，以及 Mac 用户可以检查什么。

FireAI Security & Research Team (HisnLabs) · Published 2026-10-01
Canonical: https://hisnlabs.com/zh/news/teamviewer-vulnerabilities-code-execution-remote-session

TeamViewer 于 2026 年 9 月 29 日发布了安全公告 TV-2026-1010，涉及其 Windows、Linux 和 macOS 版 Full Client 与 Host 中的五个漏洞，Cyber Security News 于 2026 年 10 月 1 日对此作了报道 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。其中两个可能导致代码执行，一个通过精心构造的会话文件，另一个通过绕过权限设置。TeamViewer 表示，未发现公开披露或正在被利用的情况 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。

## 背景

TeamViewer 是一种远程访问软件：某个人或支持技术人员连接到一台电脑，查看或控制其屏幕。该客户端还保留自己的本地服务，并能录制和回放会话。这类程序中的缺陷之所以重要，是因为程序通常拥有较广泛的权限，并且安装在同时处理工作账户和个人账户的机器上。

## 发现

公告列出了五个 CVE 编号。CVE-2026-19743 是本地 IPC 服务中的路径校验不当，评分 7.8。CVE-2026-92368 是会话回放中基于堆的缓冲区溢出，评分 7.8，影响被列为远程代码执行。CVE-2026-92369 是 Windows 安装程序回滚中的竞态条件，评分 7.3。CVE-2026-92371 是 Cloud Session Recording 中的路径校验不当，评分 7.0 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。

最严重的是 CVE-2026-92370，评分 8.8。公告把它描述为一个访问控制不当的漏洞，允许经过认证的远程攻击者绕过用户配置的权限设置 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。Cyber Security News 补充说，这有可能实现远程代码执行，而回放缺陷是在打开扩展名为 .tvs 的恶意会话文件时触发的 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/)。

修复版本是适用于所有平台的 15.82 版，同时还有针对旧版维护分支的更新。Cyber Security News 列出的受影响版本为 15.82 之前的版本，以及旧版分支 15.64、14.7 和 13.2 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。公告给出的优先级为“重要”，最高 CVSS 评分为 8.8，等级为“高”；文章标题中的“严重”一词是该媒体自己的措辞 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。

> FireAI 是 HisnLabs 开发的 macOS 本机防火墙，开启威胁数据后，它会列出存在已知安全缺陷的应用，因此过时的远程访问客户端可以被发现。可免费试用 17 天。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 对 Mac 用户的影响

公告把 macOS 列入受影响的平台，因此安装了低于 15.82 版 TeamViewer 的 Mac 在受影响范围之内 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。利用回放缺陷需要目标打开一个会话文件，利用访问控制缺陷则需要经过认证的远程攻击者，因此两者都没有被描述为对从未使用过的客户端有效 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/)。远程支持工具往往只为一次协助会话安装一次，之后就留在原处；这样的安装正是一直不会打补丁的那种。

## 建议

1. 按公告的建议，把 TeamViewer 更新到 15.82 版或最新的可用版本 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。
2. 如果客户端只是为某一次支持会话而安装、如今已不再使用，请将其卸载。
3. 不要打开来自陌生发件人的 .tvs 会话文件，因为回放缺陷正是由这类文件触发的 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/)。
4. 检查在 TeamViewer 中配置的权限设置，因为最严重的那个漏洞涉及绕过这些设置 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)。

## 与 FireAI 的关系

FireAI 不会给 TeamViewer 打补丁，不检查会话文件，也不检测对这些漏洞的利用。开启威胁数据后，[需要更新的应用](https://hisnlabs.com/en/docs/apps-that-need-an-update)会把它见到过连接的应用的版本与公开漏洞数据库作比对，并列出存在已知缺陷的应用，前提是该应用是它能在数据库中认出的；这五个 CVE 是否在其覆盖范围内，取决于数据库何时收录它们。[规则](https://hisnlabs.com/en/docs/per-app-rules)和[阻止应用](https://hisnlabs.com/en/docs/block-an-app-or-a-company)可以让用户在不需要时阻止 TeamViewer 访问互联网，[活动](https://hisnlabs.com/en/docs/activity-and-connection-history)则显示它何时发起连接。

> 已安装但不再使用的远程访问客户端仍然有一条网络通路。FireAI 可以在需要之前阻止该应用访问互联网。免费试用 17 天。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 局限

两个来源都是通过页面摘要阅读的，具体的受影响版本范围和各 CVE 的影响标签，是在无法查看公告全文的情况下从中取得的。文章与公告在语气上有差异：文章称这些漏洞为严重，而公告把最高评分评为“高”。两个来源都没有详细描述利用步骤、概念验证，或公开的攻击报告。

免费试用 [HisnLabs 的 FireAI](https://hisnlabs.com/en/download) 17 天。

## Sources

- [Cyber Security News, 1 October 2026: Critical TeamViewer vulnerabilities enable code execution attacks via remote session](https://cybersecuritynews.com/teamviewer-vulnerabilities/)
- [TeamViewer Trust Center, 29 September 2026: Security bulletin TV-2026-1010](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)
