TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data
## Cybersecurity Update on TeamViewer DEX Vulnerabilities
Cybersecurity Update on TeamViewer DEX Vulnerabilities
Critical vulnerabilities have been identified in the TeamViewer DEX Client's Content Distribution Service, specifically in NomadBranch.exe, a former component of the 1E Client.
These vulnerabilities affect Windows versions prior to 25.11 and certain older branches. They result from inadequate input validation (CWE-20), potentially allowing attackers on the local network to execute arbitrary code, crash the service, or leak sensitive data.
CVE-2025-44016: This critical vulnerability (CVSS 3.1 base score: 8.8 High) permits bypassing file integrity checks. Attackers can craft requests using valid hashes for malicious code, tricking the service into executing arbitrary code within the NomadBranch context. CVE-2025-12687: A medium-severity issue (CVSS 6.5 Medium) that triggers a denial-of-service (DoS) crash through a specially crafted command, causing the service to halt. CVE-2025-12687: Another medium-severity flaw (CVSS 4.3 Medium) that forces the service to send data to an arbitrary internal IP address, risking the exposure of sensitive information.
All vulnerabilities necessitate adjacent network access (AV:A), making them significant threats in peer-to-peer or shared LAN environments. Currently, there is no evidence of exploitation in the wild. Installations with NomadBranch disabled by default and the TeamViewer Remote/Tensor "DEX Essentials" add-on are not affected.
TeamViewer has addressed these issues in version 25.11.0.29 and has released hotfixes for legacy branches:
Release Version Download Link
These vulnerabilities affect Windows versions prior to 25.11 and certain older branches.
25.11.0.29 1E Client 25.11
25.9.0.46 (HF-PLTPKG-524) HF-PLTPKG-524
25.5.0.53 LTSB (HF-PLTPKG-526) HF-PLTPKG-526
24.5.0.69 LTSB (HF-PLTPKG-525) Support Portal
CVE-2025-46266 is resolved in version 25.11 and later. Organizations are advised to prioritize updates, verify NomadBranch status, and segment networks to mitigate risks associated with adjacent network attacks.
This disclosure highlights the importance of robust input validation in remote access tools, particularly within content distribution services.
Read more about these updates on TeamViewer's Security Bulletin.
Based on reporting by Cyber Security News.
