PT-2025-50597 · Teamviewer+1 · Teamviewer Dex+1

CVE-2025-64990

·

Publicado

2025-12-11

·

Atualizado

2025-12-11

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TeamViewer DEX (former 1E DEX) versions prior to 21.1
Description A command injection issue exists in TeamViewer DEX (formerly 1E DEX) due to improper input validation. This affects the 1E-Explorer-TachyonCore-LogoffUser instruction. An authenticated attacker with Actioner privileges can inject arbitrary commands, leading to remote execution of elevated commands on connected devices.
Recommendations Update TeamViewer DEX to version 21.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64990

Produtos afetados

1E Dex
Teamviewer Dex