CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-44016: digital employee experience before 25.11 (exclusive); +1 more affected products

CVE-2025-44016. CVSS 3.1 base score 8.8 (HIGH, Vendor/CNA). EPSS 0.00301 (percentile 0.20865), scored 2026-10-06.

Affected technology

digital employee experience · before 25.11 (exclusive)
teamviewer

DEX · 0 to before 25.11.0.29, 0 through 25.9.0.46; status changes: HF-PLTPKG-524 — unaffected, 0 through 25.5.0.53; status changes: HF-PLTPKG-526 — unaffected, 0 through 24.5.0.69; status changes: HF-PLTPKG-525 — unaffected
TeamViewer

Description’s affected range: version 25.11 for Windows

Component: Content Distribution Service, NomadBranch.exe

Attack conditions (Vendor/CNA, CVSS 3.1): Adjacent network · No privileges required · No user interaction required

What an attacker can do

An attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context. Vendor/CNA’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-20
CCR priority
35.3 /100 (P4)
CVSS 3.1
8.8 /10 · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00301 · percentile 0.20945 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-44016.html