TeamViewer DEX Privilege Escalation Vulnerability via Process Hijacking
Vulnerability
A privilege escalation vulnerability exists in TeamViewer DEX (formerly 1E DEX) versions prior to 3.4. The issue is found within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction. The vulnerability arises from improper protection of the execution path on local devices, allowing attackers with local access during execution to hijack processes and execute arbitrary code with SYSTEM privileges.
Impact
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling local attackers to execute arbitrary code with SYSTEM rights on the affected device.
Remediation
Users should update to TeamViewer DEX version 3.4 or later. Instructions for updating can be found on the TeamViewer Trust Center security bulletins page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
