Beveiligingsadvies

CVE-2025-66575

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-04 20:46:08
Laatst bijgewerkt 2025-12-05 17:44:47
Toegewezen door VulnCheck
CVSS-score 8.5
Status PUBLISHED

Beschrijving

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.