Code Execution Vulnerability in Tenable Agent on Windows
CVE-2025-36632

7.8HIGH

Key Information:

Vendor

Tenable

Status
Vendor
CVE Published:
16 June 2025

What is CVE-2025-36632?

A vulnerability exists in Tenable Agent versions prior to 10.8.5 that allows non-administrative users on Windows hosts to execute code with SYSTEM privileges. This flaw could potentially enable unauthorized access to sensitive system functions and lead to further exploitation, making it crucial for users to update their software to maintain security.

Affected Version(s)

Agent Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36632 : Code Execution Vulnerability in Tenable Agent on Windows