CVE-2025-64993: Command Injection in 1E-ConfigMgrConsoleExtensions Instructions
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64993?
CVE-2025-64993 is classified as a critical command injection vulnerability.
How do I fix CVE-2025-64993?
To fix CVE-2025-64993, update to the latest version of TeamViewer DEX that includes patches for this vulnerability.
Who is affected by CVE-2025-64993?
CVE-2025-64993 affects authenticated users with Actioner privileges in TeamViewer DEX.
What type of vulnerability is CVE-2025-64993?
CVE-2025-64993 is a command injection vulnerability due to improper input validation.
Can attackers exploit CVE-2025-64993 remotely?
Yes, attackers can exploit CVE-2025-64993 remotely if they have authenticated access with Actioner privileges.