Advisories

VeeVPN v1.6.1 - Unquoted Service Path Remote Code Execution

Go Back
severity
high
date
Affecting
  • VeeVPN v1.6.1

CVE type
CWE-428 Unquoted Search Path or Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Credit
Doöukan Orhan
Description
VeeVPN v1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.