Description
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. This does not impact Linux or OSX Secure Connector.
INFO
Published Date :
2025-05-13T17:34:53.955Z
Last Modified :
2025-08-21T15:14:15.922Z
Source :
Forescout
AFFECTED PRODUCTS
The following products are affected by CVE-2025-4660 vulnerability.
| Vendors | Products |
|---|---|
| Forescout |
|
| Microsoft |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-4660.
| URL | Resource |
|---|---|
| https://forescout.my.site.com/support/s/article/ |
|