Local Privilege Escalation in Nessus Versions by Tenable
CVE-2025-24914
7.8HIGH
What is CVE-2025-24914?
Recent findings have highlighted a local privilege escalation vulnerability in Nessus that affects versions prior to 10.8.4. When Nessus is installed to a non-default location on a Windows system, the application fails to enforce secure permissions for its sub-directories. This oversight can potentially be exploited by users, leading to unauthorized access and increased privileges in the system if the directories remain unsecured. It is crucial for users installing Nessus to adhere to default installation procedures or to implement strict security measures for custom installation locations to mitigate this risk.
Affected Version(s)
Nessus Windows 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published