{"id":"CVE-2025-64993","title":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions","summary":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges …","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-77"],"vendor":"teamviewer","product":"digital_employee_experience","affected":["digital_employee_experience < 29.0"],"patched":["digital_employee_experience 29.0"],"published":"2025-12-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64993","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/","label":"psirt@teamviewer.com"}],"tags":["nvd"],"epss":0.00872,"epssPercentile":0.57602,"ingestedAt":"2026-10-08T10:28:24.837Z","slug":"CVE-2025-64993","body":"## Overview\n\nA command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.\n\n## Affected\n\n- `digital_employee_experience < 29.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `digital_employee_experience 29.0`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}