CVE-2026-23563
Privilege escalation in TeamViewer DEX via DeleteFileByPath instruction
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the delete instruction executes.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H
Affected products
TeamViewer · DEXWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →