Improper Access Controls in Cisco ThousandEyes Endpoint Agent for Windows
CVE-2025-20259

5.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 June 2025

Badges

👾 Exploit Exists

What is CVE-2025-20259?

The Cisco ThousandEyes Endpoint Agent for Windows has vulnerabilities during its update process that could be exploited by an authenticated local attacker. These vulnerabilities stem from inadequate access controls on local file system files. An attacker can use symbolic links to manipulate agent upgrades, leading to unauthorized deletion of crucial files. Successful exploitation poses significant risks by allowing the deletion of arbitrary files from the device's file system.

Affected Version(s)

Cisco ThousandEyes Endpoint Agent

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.