CVE-2025-20259 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary…
Medium CVSS: 5.3

CVE-2025-20259

Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device.

These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit these vulnerabilities by using a symbolic link to perform an agent upgrade that redirects the delete operation of any protected file. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.
Vendor
Cisco
Product
Thousandeyes Endpoint Agent
CWE
CWE-22
Yayın Tarihi
2025-06-04 17:15:26
Güncelleme
2025-07-22 15:31:19
Source Identifier
psirt@cisco.com
KEV Date Added
-

Kategoriler

Referanslar