PT-2017-17145 · Tenable+1 · Tenable Appliance+3
Published
2017-03-08
·
Updated
2019-10-03
·
CVE-2017-6543
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenable Nessus versions prior to 6.10.2
Tenable Appliance versions prior to 4.5.0
Description
The issue allows a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system, for example, after a reboot. This issue only affects installations on Windows.
Recommendations
For Tenable Nessus versions prior to 6.10.2, update to version 6.10.2 or later to resolve the issue.
For Tenable Appliance versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nessus
Tenable Appliance
Tenable Nessus
Windows