CVE-2025-64994

Name
CVE-2025-64994
Description
A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute arbitrary code as SYSTEM.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
psirt@teamviewer.com https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/

Match rules

CPE URI Source package Min version Max version
dex == 0 == None
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* digital_employee_experience >= None < 17.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dex edge-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.23-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.22-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable