Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2025-44016

 

Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2025-44016

Published: December 11, 2025


Vulnerability identifier: #VU119844
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-44016
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of file hash in the Content Distribution Service (NomadBranch.exe). A remote attacker on the local network can supply a valid hash for a malicious file and force the service to incorrectly validate and process the file as trusted, leading to remote code execution. 


Affected software

Digital Employee Experience (DEX) Client for Windows

How to mitigate CVE-2025-44016

Install updates from vendor's website.

Digital Employee Experience (DEX) Client for Windows - addressed in versions 24.5.0.69, 25.5.0.53, 25.9.0.46, 25.11.0.29

External References

Related Security Bulletins