CVE-2020-15261

HIGH

Veyon Service <4.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-15261. PoCs published by Víctor García.

AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in Veyon 4.4.1. The vulnerability could allow local privilege escalation if an attacker can place an executable in a path that is executed due to improper quoting.

Description

On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students and teachers) usually don't have administrative privileges, this vulnerability is only dangerous in anyway unsafe setups. The problem has been fixed in version 4.4.2. As a workaround, the exploitation of the vulnerability can be prevented by revoking administrative privileges from all potentially untrustworthy users.

Exploits (2)

exploitdb WRITEUP
by Víctor García · textlocalwindows
https://www.exploit-db.com/exploits/49925

This is a writeup describing an unquoted service path vulnerability in Veyon 4.4.1. The vulnerability could allow local privilege escalation if an attacker can place an executable in a path that is executed due to improper quoting.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Veyon 4.4.1
Auth required
Prerequisites: Local access to the system · Ability to write to a directory in the unquoted path
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
by Víctor García · textlocalwindows
https://www.exploit-db.com/exploits/48246

This is a writeup describing an unquoted service path vulnerability in Veyon 4.3.4. The vulnerability could allow local privilege escalation if an attacker can place executable code in the system root path.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Veyon 4.3.4
Auth required
Prerequisites: Local access to the system · Ability to write to the system root path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/veyon/veyon/issues/657
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/162873/Veyon-4.4.1-Unquoted-Service-Path.html
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49925
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/48246

Scores

CVSS v3 8.0
EPSS 0.1112
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
veyon/veyon < 4.4.2
Published Oct 19, 2020
Tracked Since Feb 18, 2026