Where
-Infinity
0
Severity
6.5
EPSS
0.03%
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
7.5
EPSS
0.05%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR remotely and facilitate exploitation of other vulnerabilities on the affected system.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
8.1
EPSS
0.01%
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be used to bypass ASLR and facilitate further exploitation.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.5
EPSS
0.02%
Buffer Overflow
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted UDP packets.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.5
EPSS
0.03%
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log integrity and nonrepudiation.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.5
EPSS
0.03%
Null Pointer Dereference
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content Distribution Service.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.5
EPSS
0.01%
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.8
EPSS
0.11%
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected into the instruction’s input field. Users of 1E Client version 24.5 or higher are not affected.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version. Remove the instruction 1E-Nomad-RunPkgStatusRequest from DEX Portal.
First published (updated )
Severity
7.1
EPSS
0.03%
AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H

Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the delete instruction executes.

Remedy

Update the TeamViewer DEX Client (1E Client) to the latest available version.
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution, to hijack the process and execute arbitrary code with SYSTEM privileges.

Remedy

Update to the latest available versions (v3.4 or later).
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute arbitrary code as SYSTEM.

Remedy

On-prem users should update to the latest available version (v17.1 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available versions. SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available version (v25 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available version (v15 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available version (v21.1 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available version (v21.1 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users should update to the latest available version (v19.2 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

Instruction has been discontinued. Delete instruction from platform.
First published (updated )
Severity
7.2
Input Validation, Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

Remedy

On-prem users: Update to the latest available version (v21 or later). SaaS instances have been updated automatically.
First published (updated )
Severity
6.5
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.

Remedy

Update the TeamViewer DEX Client to the latest available version (25.11 or above).
First published (updated )
Severity
8.8
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.

Remedy

Update the TeamViewer DEX client to the latest available version.
First published (updated )
Severity
6.5
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to cause a denial of service (application crash) via a crafted command, resulting in service termination.

Remedy

Update the TeamViewer DEX client to the latest available version.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203