1. Summary
Command Injection and Privilege Escalation vulnerabilities were identified in TeamViewer DEX (former 1E DEX).
The vulnerabilities have been fixed with new versions listed below.
At this time, there is no indication that these vulnerabilities have been exploited in the wild.
2. Vulnerability Details
2.1 Privilege escalation in TeamViewer DEX - DeleteFileByPath instruction
2.2 Command Injection in 1E-Nomad-RunPkgStatusRequest Instruction in TeamViewer DEX
3. Solutions and mitigations
4. Acknowledgments
We would like to thank the Lockheed Martin Red Team for the discovery and responsible disclosure.