CVE-2025-66575

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.
Configurations

Configuration 1 (hide)

cpe:2.3:a:veepn:veepn:1.6.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-04 21:16

Updated : 2025-12-30 16:33


NVD link : CVE-2025-66575

Mitre link : CVE-2025-66575

CVE.ORG link : CVE-2025-66575


JSON object : View

Products Affected

veepn

  • veepn
CWE
CWE-428

Unquoted Search Path or Element