CVE-2025-64995

Name
CVE-2025-64995
Description
A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution, to hijack the process and execute arbitrary code with SYSTEM privileges.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
psirt@teamviewer.com https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/

Match rules

CPE URI Source package Min version Max version
dex == 0 == None
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* digital_employee_experience >= None < 3.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dex edge-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.23-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable
dex 3.22-community 0.10.1-r0 Anjandev Momi <anjan@momi.ca> possibly vulnerable