Aller au contenu

Fiche vulnérabilité

CVE-2025-64991 : faille élevée teamviewer digital employee experience (CVSS 7.2)

Description

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • teamviewer digital employee experience

Références

Rechercher une autre vulnérabilité dans la base CVE