PT-2025-49151 · Veevpn · Veevpn
Published
2025-12-04
·
Updated
2025-12-30
·
CVE-2025-66575
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
VeeVPN version 1.6.1
Description
VeeVPN version 1.6.1 has an issue with an unquoted service path in the VeePNService. This allows remote attackers to potentially run code when the system starts or restarts, gaining higher privileges. An attacker can exploit this by supplying a malicious service name, which allows them to inject commands and operate as LocalSystem.
Recommendations
Update VeeVPN to a version with a fix for this issue. As a temporary workaround, consider restricting the service name allowed for the VeePNService.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veevpn