Forescout SecureConnector Windows Agent Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the Windows agent component of Forescout SecureConnector. This issue arises from improper access controls on a named pipe, which is accessible to the Everyone group and lacks restrictions on remote connections. As a result, any network-based attacker can connect to the pipe without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. This vulnerability does not affect the Linux or OSX versions of SecureConnector.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
5.7
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.