CVE-2025-4660
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. This does not impact Linux or OSX Secure Connector.
- Affected products
- Secureconnector
- Forescout Secureconnector
- < 11.3.7
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-276
- NVD status
- Analyzed
- Published
- 2025-05-13
- Attack patterns
- CAPEC-549
CVE-2025-4660 at NVD
1 known exploit for CVE-2025-4660
Proof-of-concept code and exploit modules indexed by Sploitus