Data Transmission Vulnerability in TeamViewer DEX Client for Windows
CVE-2025-46266

4.3MEDIUM

Key Information:

Vendor

Teamviewer

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-46266?

The TeamViewer DEX Client (formerly known as the 1E Client) for Windows is susceptible to a vulnerability whereby the Content Distribution Service (NomadBranch.exe) can be manipulated by malicious actors. This may allow unauthorized data transmission to an arbitrary internal IP address, posing a significant risk of sensitive information leakage. Users of versions prior to 25.11 should be vigilant regarding this security concern and consider promptly updating to secure their systems.

Affected Version(s)

DEX Windows 0 < 25.11.0.29

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Threat Hunt Team of Bank of America
.