CVE-2025-44016
8.8TeamViewer · DEX Client (NomadBranch)
A vulnerability in the TeamViewer DEX Client Content Distribution Service allows attackers to bypass file integrity validation and achieve arbitrary code execution via crafted requests.
Executive summary
A critical vulnerability in the TeamViewer DEX Client allows unauthenticated attackers to execute arbitrary code with elevated service privileges, posing a severe risk to system integrity.
Vulnerability
The flaw exists within the NomadBranch.exe service, where improper input validation allows an unauthenticated attacker to bypass file integrity checks. By supplying a crafted request with a valid hash for a malicious file, an attacker can trick the service into processing the file as trusted, leading to arbitrary code execution under the Nomad Branch service context.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code with service-level privileges constitutes a high-severity risk. This vulnerability could lead to total system compromise, unauthorized data access, and the potential for lateral movement within the network. Given the CVSS score of 8.8, this flaw represents a significant threat to operational security and business continuity.
Remediation
Immediate Action: Update the TeamViewer DEX client to version 25.11.0.29 or later to remediate the file integrity validation flaw.
Proactive Monitoring: Review system logs for suspicious activity originating from the NomadBranch service and monitor for unauthorized file execution attempts.
Compensating Controls: Implement network segmentation to restrict access to the NomadBranch service, ensuring it is not reachable by untrusted entities.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system compromise, organizations currently running affected versions of the TeamViewer DEX client should prioritize patching. Apply the vendor-provided update immediately to eliminate the risk of arbitrary code execution and ensure that the Nomad Branch service is properly configured to validate file integrity.
More TeamViewer CVEs
Sources
Originally found and disclosed by Threat Hunt Team of Bank of America, per the CVE Program record.