A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veepn
Veepn veepn |
|
| Vendors & Products |
Veepn
Veepn veepn |
Mon, 27 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | VeePN AVService avservice.exe unquoted search path | |
| Weaknesses | CWE-426 CWE-428 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-27T14:02:08.168Z
Updated: 2025-10-27T14:02:08.168Z
Reserved: 2025-10-26T16:23:28.429Z
Link: CVE-2025-12286
No data.
Status : Received
Published: 2025-10-27T14:15:40.190
Modified: 2025-10-27T14:15:40.190
Link: CVE-2025-12286
No data.
ReportizFlow