CVE-2025-66575
VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Affected
- veepn/veepn
- Source
- disclosure@vulncheck.com
References
- https://github.com/veepn/veepnBroken Link
- https://veepn.com/Product
- https://www.exploit-db.com/exploits/52088Exploit
- https://www.vulncheck.com/advisories/veevpn-161-unquoted-service-path-remote-code-executionThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/52088Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.