Get real-time updates on Telegram
CVE-2025-44016: digital employee experience before 25.11 (exclusive); +1 more affected products
CVE-2025-44016. CVSS 3.1 base score 8.8 (HIGH, Vendor/CNA). EPSS 0.00301 (percentile 0.20865), scored 2026-10-06.
Affected technology
digital employee experience · before 25.11 (exclusive)
teamviewer
DEX · 0 to before 25.11.0.29, 0 through 25.9.0.46; status changes: HF-PLTPKG-524 — unaffected, 0 through 25.5.0.53; status changes: HF-PLTPKG-526 — unaffected, 0 through 24.5.0.69; status changes: HF-PLTPKG-525 — unaffected
TeamViewer
Description’s affected range: version 25.11 for Windows
Component: Content Distribution Service, NomadBranch.exe
Attack conditions (Vendor/CNA, CVSS 3.1): Adjacent network · No privileges required · No user interaction required
What an attacker can do
An attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context. Vendor/CNA’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-20
- CCR priority
- 35.3 /100 (P4)
- CVSS 3.1
- 8.8 /10 · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00301 · percentile 0.20945 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-44016.html