CVE-2025-64988
7.2TeamViewer · DEX (formerly 1E DEX)
A command injection vulnerability in the 1E-Nomad-GetCmContentLocations instruction of TeamViewer DEX allows authenticated attackers with Actioner privileges to execute arbitrary commands.
Executive summary
A command injection vulnerability in TeamViewer DEX poses a critical risk of remote code execution for organizations that have not updated to version 19.2 or later.
Vulnerability
This vulnerability stems from improper input validation within the 1E-Nomad-GetCmContentLocations instruction, which can be leveraged by authenticated attackers with Actioner privileges to execute elevated commands.
Business impact
The ability for an authenticated attacker to inject and execute arbitrary commands with elevated privileges represents a severe security compromise. Successful exploitation could lead to full system takeover, unauthorized access to sensitive data, and the potential for lateral movement across the internal network. With a CVSS score of 7.2, this vulnerability is considered a high-severity risk that requires immediate attention to prevent operational disruption and data loss.
Remediation
Immediate Action: On-premise users must update their TeamViewer DEX instances to version 19.2 or later immediately. SaaS instances have been updated automatically by the vendor.
Proactive Monitoring: Security teams should monitor system logs for unusual command execution patterns or unauthorized access attempts originating from accounts with Actioner privileges.
Compensating Controls: Ensure that access to the management console is restricted to authorized personnel via multi-factor authentication to limit the pool of potential attackers.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for remote code execution, organizations should prioritize the deployment of version 19.2 across all on-premise TeamViewer DEX installations. Verify that all systems have successfully received the update to ensure the vulnerable instruction set is properly patched.
More TeamViewer CVEs
Sources
Originally found and disclosed by Lockheed Martin Red Team, per the CVE Program record.