Unquoted Service Path Vulnerability in VeePN by VeeVPN
CVE-2025-66575
Key Information:
Badges
What is CVE-2025-66575?
VeeVPN 1.6.1 is vulnerable to an unquoted service path issue within the VeePNService. This flaw allows remote attackers to exploit the service during startup or reboot processes to execute arbitrary code with escalated privileges. By providing a malicious service name, attackers can inject harmful commands that execute under the LocalSystem account, potentially compromising the system's integrity and confidentiality. For more information, see the advisories and resources linked below.
Affected Version(s)
VeeVPN 1.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
