CVE-2025-4660

CRITICAL

SecureConnector - RCE

Title source: llm

Description

A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.  This does not impact Linux or OSX Secure Connector.

Exploits (1)

nomisec WORKING POC 16 stars
by NetSPI · poc
https://github.com/NetSPI/CVE-2025-4660

Scores

CVSS v3 9.8
EPSS 0.0152
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-276
Status published

Affected Products (1)

forescout/secureconnector < 11.3.7

Timeline

Published May 13, 2025
Tracked Since Feb 18, 2026