A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.
History

Thu, 11 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Teamviewer
Teamviewer dex
Vendors & Products Microsoft
Microsoft windows
Teamviewer
Teamviewer dex

Thu, 11 Dec 2025 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.
Title Unauthenticated Transmission of Data in NomadBranch.exe
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published: 2025-12-11T11:25:11.980Z

Updated: 2025-12-11T17:11:43.556Z

Reserved: 2025-04-30T08:08:15.972Z

Link: CVE-2025-46266

cve-icon Vulnrichment

Updated: 2025-12-11T17:11:40.296Z

cve-icon NVD

Status : Received

Published: 2025-12-11T12:16:25.270

Modified: 2025-12-11T12:16:25.270

Link: CVE-2025-46266

cve-icon Redhat

No data.