CVE-2025-64994: TeamViewer Digital Employee Experience

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute arbitrary code as SYSTEM.

Affected products

  • TeamViewer Digital Employee Experience: before 17.1 (fixed in 17.1)

Published 2025-12-11. Last modified 2026-10-08.