CVE-2025-64989
7.2TeamViewer · DEX
A command injection vulnerability in TeamViewer DEX allows authenticated attackers with Actioner privileges to execute arbitrary commands on connected devices due to improper input validation.
Executive summary
A high-severity command injection vulnerability in TeamViewer DEX poses a significant risk of remote code execution for organizations relying on the platform for device management.
Vulnerability
This is a command injection flaw (CWE-20) located within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction. The vulnerability requires the attacker to hold Actioner privileges, allowing them to bypass input validation and execute elevated commands on affected endpoints.
Business impact
The ability for an authenticated attacker to inject and execute arbitrary commands represents a critical failure in system integrity. Successful exploitation could lead to full device compromise, unauthorized data exfiltration, or the deployment of persistent malware across the enterprise environment. Given the CVSS score of 7.2, this vulnerability demands immediate attention to prevent potential lateral movement and unauthorized administrative control.
Remediation
Immediate Action: On-premises users must update their TeamViewer DEX instances to version 21.1 or later immediately. SaaS instances have already been updated automatically by the vendor.
Proactive Monitoring: Security teams should review audit logs for the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction for suspicious patterns or unexpected command execution attempts.
Compensating Controls: Implement strict role-based access control to limit the number of users with Actioner privileges, effectively reducing the potential attack surface while the update is deployed.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Organizations should prioritize the update of any on-premises TeamViewer DEX infrastructure to version 21.1 without delay. Because this vulnerability allows for remote execution of elevated commands, failing to patch exposes the environment to significant risk of unauthorized administrative access. Please verify your current version and apply the vendor-provided patch to ensure your environment remains secure.
More TeamViewer CVEs
Sources
Originally found and disclosed by Lockheed Martin Red Team, per the CVE Program record.