---
id: CVE-2025-64995
title: >-
  A privilege escalation vulnerability was discovered in TeamViewer DEX (former
  1E DEX), specifically within the
  1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4
summary: >-
  A privilege escalation vulnerability was discovered in TeamViewer DEX (former
  1E DEX), specifically within the
  1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4.
  Improper protection of the execution path on the…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: teamviewer
product: digital_employee_experience
affected:
  - digital_employee_experience < 3.4
patched:
  - digital_employee_experience 3.4
published: '2025-12-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64995'
references:
  - url: >-
      https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/
    label: psirt@teamviewer.com
tags:
  - nvd
epss: 0.00166
epssPercentile: 0.05324
ingestedAt: '2026-10-08T10:28:24.844Z'
---

## Overview

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution, to hijack the process and execute arbitrary code with SYSTEM privileges.

## Affected

- `digital_employee_experience < 3.4`

## Remediation

Upgrade past the affected range:

- `digital_employee_experience 3.4`
