TeamViewer DEX Client NomadBranch Data Transmission Vulnerability
Vulnerability
A vulnerability exists in the TeamViewer DEX Client Content Distribution Service (NomadBranch.exe) for Windows, prior to version 25.11. This vulnerability allows malicious actors to manipulate the service into sending data to an arbitrary internal IP address, which could result in the unintentional leakage of sensitive information. Exploitation requires local network-level access.
Impact
Exploitation of this vulnerability could lead to unauthorized data transmission to an internal IP address, potentially causing a leak of sensitive information.
Remediation
Users can update to TeamViewer DEX Client version 25.11.0.29 or later. For those using the 1E Client, versions 25.9.0.46 (Hotfix), 25.5.0.53 (Hotfix), and 24.5.0.69 (Hotfix) are also available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
