Fiche vulnérabilité
CVE-2025-64991 : faille élevée teamviewer digital employee experience (CVSS 7.2)
Description
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
En bref
- Sévérité
- Élevée (CVSS 7.2)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 11 déc. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- teamviewer digital employee experience