CVE-2025-64994 is a privilege escalation vulnerability in TeamViewer DEX (formerly 1E DEX) versions prior to V17.1, specifically within the 1E-Nomad-SetWorkRate instruction. This flaw, rated Medium severity with a CVSS score of 6.7, allows local attackers with write access to a PATH directory to execute arbitrary code as SYSTEM due to improper handling of executable search paths. While the potential impact is high for confidentiality, integrity, and availability, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.1CPE matchmatch criteria | cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.