CVE-2026-23569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
29/01/2026
Last modified:
11/02/2026

Description

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR remotely and facilitate exploitation of other vulnerabilities on the affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* 26.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*