CVE-2025-4660: Forescout Secureconnector

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.  This does not impact Linux or OSX Secure Connector.

Affected products

  • Forescout Secureconnector: from 11.1.02.1019, before 11.3.7 (fixed in 11.3.7)

Published 2025-05-13. Last modified 2026-06-17.