CVE-2020-37101: Vpnunlimitedapp VPN Unlimited

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious executables into the service binary path. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\VPN Unlimited\' to replace the service executable and gain elevated system privileges.

Affected products

Published 2026-02-03. Last modified 2026-06-17.