Critical Security Bypass in Veyon Lock Screen (Win+Alt+D)
-
Hello,
I am writing to report a critical security vulnerability in the Veyon lock screen feature. The lock screen can be completely bypassed using a specific keyboard shortcut.
Please note that English is not my first language. I have done my best to describe the issue clearly below.
Description:
The Veyon lock screen does not block the Windows Key + Alt + D (Win+Alt+D) shortcut. Pressing this combination will bypass the lock and provide full access to the desktop.Steps to Reproduce:
Lock a computer session using Veyon.
On the active lock screen, press the Win + Alt + D keys together.
Observe that the Windows "New Desktop" feature is triggered, effectively hiding the Veyon lock screen and granting access to the original desktop.
Expected Result:
The lock screen should disable all system-level keyboard shortcuts and remain secure.Actual Result:
The Win+Alt+D shortcut is allowed to execute, creating a new virtual desktop and bypassing the lock screen's protection.Environment:
Veyon Version: 4.9.7
Operating System: Windows 10
Thank you for looking into this issue. This is a serious security flaw that compromises the integrity of the lock screen. I hope this report helps in resolving it promptly.
