Multiple critical and high-severity vulnerabilities have been discovered in the TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), affecting Windows versions prior to 25.11 and certain legacy branches. The most severe flaw, CVE-2025-44016 (CVSS 8.8), allows attackers on the local network to bypass file integrity checks and execute arbitrary code by submitting a request with a valid hash for malicious code. Additional vulnerabilities include CVE-2025-12687, which can trigger a denial-of-service (DoS) crash, and another flaw that enables the service to send sensitive data to arbitrary internal IP addresses, risking data exposure. All issues require adjacent network access, making them particularly relevant in peer-to-peer or shared LAN environments, but there is currently no evidence of exploitation in the wild.
TeamViewer has addressed these vulnerabilities in version 25.11.0.29 and released hotfixes for affected legacy branches. Organizations are advised to update to the latest versions, verify the status of the NomadBranch service, and implement network segmentation to mitigate the risk of adjacent network attacks. Installations with NomadBranch disabled by default and the TeamViewer Remote/Tensor “DEX Essentials” add-on are not affected. The disclosure highlights the importance of robust input validation and timely patch management for remote access and content distribution tools.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
TeamViewer released patches in version 25.11.0.29 and hotfixes for legacy branches to address the disclosed NomadBranch vulnerabilities. The company advised organizations to update affected systems, check whether NomadBranch is enabled, and use network segmentation to reduce risk.
Multiple vulnerabilities were identified in TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), including CVE-2025-44016, which could let an adjacent-network attacker bypass file integrity checks and execute arbitrary code, and CVE-2025-12687 issues that could cause denial of service or expose sensitive data. The flaws affect Windows versions prior to 25.11 and certain legacy branches, with no evidence of exploitation in the wild reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.