CVE-2020-15261

Source
https://cve.org/CVERecord?id=CVE-2020-15261
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15261.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-15261
Aliases
  • GHSA-c8cc-x786-hqqp
Published
2020-10-19T22:15:13.093Z
Modified
2026-07-09T10:52:29.658455Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students and teachers) usually don't have administrative privileges, this vulnerability is only dangerous in anyway unsafe setups. The problem has been fixed in version 4.4.2. As a workaround, the exploitation of the vulnerability can be prevented by revoking administrative privileges from all potentially untrustworthy users.

References

Affected packages

Git / github.com/veyon/veyon

Affected ranges

Type
GIT
Repo
https://github.com/veyon/veyon
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:veyon:veyon:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.4.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v3.*
v3.99.0
v3.99.1
v3.99.2
v3.99.3
v3.99.4
v3.99.5
v3.99.6
v3.99.7
v4.*
v4.0.0
v4.0.1
v4.0.90
v4.0.91
v4.0.92
v4.1.0
v4.1.1
v4.1.2
v4.1.90
v4.1.91
v4.1.92
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.99.0

Database specific

vanir_signatures
[
    {
        "source": "https://github.com/veyon/veyon/commit/f231ec511b9a09f43f49b2c7bb7c60b8046276b1",
        "signature_version": "v1",
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "272118001296872365787519925518929597588",
                "275342087029539659717202817469162695245",
                "163600722140506002111636782884147320458",
                "118613466315895221819147265198958329498",
                "160732023610005516958705917526652610159",
                "24231635469766302601441547201643366241",
                "256975937652514861376594475042041235699",
                "258769395570646887833924535121040133852"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2020-15261-1e952060",
        "target": {
            "file": "plugins/platform/windows/WindowsServiceControl.cpp"
        }
    },
    {
        "source": "https://github.com/veyon/veyon/commit/f231ec511b9a09f43f49b2c7bb7c60b8046276b1",
        "signature_version": "v1",
        "signature_type": "Function",
        "digest": {
            "function_hash": "290294997321056731839350118888527666391",
            "length": 1219.0
        },
        "deprecated": false,
        "id": "CVE-2020-15261-472fe8e6",
        "target": {
            "function": "WindowsServiceControl::install",
            "file": "plugins/platform/windows/WindowsServiceControl.cpp"
        }
    }
]
vanir_signatures_modified
"2026-07-09T10:52:29Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15261.json"