| ID |
CVE-2025-12286
|
| Sažetak |
A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way. |
| Reference |
|
| CVSS |
| Base: | 6.0 |
| Impact: | 10.0 |
| Exploitability: | 1.5 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
HIGH |
SINGLE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:L/AC:H/Au:S/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
27-10-2025 - 14:15 |
| Objavljeno |
27-10-2025 - 14:15 |