Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit these vulnerabilities by using a symbolic link to perform an agent upgrade that redirects the delete operation of any protected file. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.
History

Wed, 04 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit these vulnerabilities by using a symbolic link to perform an agent upgrade that redirects the delete operation of any protected file. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.
Title Cisco ThousandEyes Endpoint Agent for Windows Arbitrary File Write Vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-06-04T16:22:01.245Z

Updated: 2025-06-04T18:19:11.860Z

Reserved: 2024-10-10T19:15:13.242Z

Link: CVE-2025-20259

cve-icon Vulnrichment

Updated: 2025-06-04T18:12:26.256Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-04T17:15:26.620

Modified: 2025-06-05T20:12:23.777

Link: CVE-2025-20259

cve-icon Redhat

No data.