CVE-2025-44016

Name
CVE-2025-44016
Description
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
psirt@teamviewer.com https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1005/

Match rules

CPE URI Source package Min version Max version
dex == 0 == None
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* digital_employee_experience >= None < 25.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dex edge-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.23-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.22-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable