CVE-2026-23563: Privilege escalation in TeamViewer DEX via DeleteFileByPath instruction
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the delete instruction executes.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23563?
CVE-2026-23563 has been classified as a privilege escalation vulnerability that allows local attackers to gain elevated permissions.
How do I fix CVE-2026-23563?
To mitigate CVE-2026-23563, update TeamViewer DEX - 1E Client to version 26.1 or later.
What systems are affected by CVE-2026-23563?
CVE-2026-23563 affects TeamViewer DEX - 1E Client versions prior to 26.1 on Windows.
What type of vulnerability is CVE-2026-23563?
CVE-2026-23563 is a privilege escalation vulnerability that allows local attackers to manipulate file access permissions.
Can CVE-2026-23563 be exploited remotely?
No, CVE-2026-23563 requires local access to the system to be exploited.