TeamViewer DEX Privilege Escalation Vulnerability via Process Hijacking

Vulnerability

A privilege escalation vulnerability exists in TeamViewer DEX (formerly 1E DEX) versions prior to 3.4. The issue is found within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction. The vulnerability arises from improper protection of the execution path on local devices, allowing attackers with local access during execution to hijack processes and execute arbitrary code with SYSTEM privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling local attackers to execute arbitrary code with SYSTEM rights on the affected device.

Remediation

Users should update to TeamViewer DEX version 3.4 or later. Instructions for updating can be found on the TeamViewer Trust Center security bulletins page.

Added: Dec 11, 2025, 12:18 PM
Updated: Dec 11, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.