Privilege Escalation Vulnerability in TeamViewer DEX Software
CVE-2025-64995

6.5MEDIUM

Key Information:

Vendor

Teamviewer

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-64995?

A serious privilege escalation vulnerability has been identified in TeamViewer DEX, previously known as 1E DEX. This flaw resides in the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior to version 3.4. It stems from inadequate protection of the execution path on local devices, potentially allowing attackers with local access during execution to seize control of the process and execute arbitrary code with SYSTEM privileges. This exploitation poses a significant threat to affected systems, emphasizing the need for immediate attention and remediation.

Affected Version(s)

DEX 0 < 3.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lockheed Martin Red Team
.