CVE-2025-64987

7.2

TeamViewer · DEX

A command injection vulnerability exists in TeamViewer DEX due to improper input validation in the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction, allowing command execution by authenticated users.

Executive summary

An authenticated command injection vulnerability in TeamViewer DEX allows remote attackers with Actioner privileges to execute arbitrary commands on connected devices, posing a high security risk.

Vulnerability

This is a command injection vulnerability (CWE-20) residing within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. It requires the attacker to hold authenticated Actioner privileges to successfully inject and execute elevated commands on the target environment.

Business impact

The ability to execute arbitrary commands with elevated privileges on managed devices represents a significant threat to internal infrastructure. A successful exploit could lead to full system compromise, unauthorized data access, and loss of control over the affected endpoints. With a CVSS score of 7.2, this vulnerability is categorized as High severity and requires prompt attention to prevent lateral movement within the network.

Remediation

Immediate Action: The vendor has discontinued the vulnerable instruction; administrators should delete the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction from the platform immediately.

Proactive Monitoring: Review audit logs for unusual activity associated with accounts holding Actioner privileges and monitor for unexpected process execution on managed endpoints.

Compensating Controls: Restrict access to the Actioner role to the minimum number of necessary personnel and utilize network segmentation to limit the reach of managed devices.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution, organizations should treat this vulnerability with high urgency. Because the recommended fix involves the removal of a specific instruction rather than a traditional patch, security teams must verify the removal across all managed instances to ensure complete remediation.

More TeamViewer CVEs

Sources

Originally found and disclosed by Lockheed Martin Red Team, per the CVE Program record.