On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students and teachers) usually don't have administrative privileges, this vulnerability is only dangerous in anyway unsafe setups. The problem has been fixed in version 4.4.2. As a workaround, the exploitation of the vulnerability can be prevented by revoking administrative privileges from all potentially untrustworthy users.
Conclusion & alert: CVE-2020-15261 is rated High Exploit Risk (83.4/100): CVSS High severity, with high exploitation likelihood (EPSS 11.12%, 95th percentile). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.07% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 49925 | exploit_db | edb | 2021-06-01 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 8.06% | 11.12% | +3.07% |
| 2 | 2025-11-21 | 1.85% | 8.06% | +6.20% |
| 3 | 2025-11-18 | — | 1.85% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.0 | 3.1 | HIGH |
|
1.3 | 6.0 | [email protected] |
| 6.7 | 3.1 | MEDIUM |
|
0.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2020-15261 unimportant priority: Debian including 1 source packages (veyon), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-15261 |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/162873/Veyon-4.4.1-Unquoted-Service-Path.html | Exploit Third Party Advisory VDB Entry |
| https://github.com/veyon/veyon/commit/f231ec511b9a09f43f49b2c7bb7c60b8046276b1 | Patch Third Party Advisory |
| https://github.com/veyon/veyon/issues/657 | Issue Tracking Third Party Advisory |
| https://github.com/veyon/veyon/security/advisories/GHSA-c8cc-x786-hqqp | Third Party Advisory |
| https://www.exploit-db.com/exploits/48246 | Exploit Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/49925 | Exploit Third Party Advisory VDB Entry |