CVE-2025-4660: Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.
This does not impact Linux or OSX Secure Connector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4660?
CVE-2025-4660 is classified as a high-severity remote code execution vulnerability.
How do I fix CVE-2025-4660?
To fix CVE-2025-4660, upgrade the Windows Secure Connector to a version that addresses the improper access controls on the named pipe.
What type of attacks can exploit CVE-2025-4660?
CVE-2025-4660 can be exploited by network-based attackers who can leverage the unrestrictive access to execute arbitrary code.
Which versions of SecureConnector are affected by CVE-2025-4660?
CVE-2025-4660 affects all versions of the Windows Secure Connector prior to the security fix provided in the latest updates.
Is user authentication required to exploit CVE-2025-4660?
No, user authentication is not required to exploit CVE-2025-4660 due to the accessibility of the named pipe to the Everyone group.